Vulnerabilities > Apple > MAC OS X

DATE CVE VULNERABILITY TITLE RISK
2008-03-18 CVE-2008-0055 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.
local
low complexity
apple CWE-362
7.2
2008-03-18 CVE-2008-0054 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.
network
low complexity
apple CWE-20
6.4
2008-03-18 CVE-2008-0052 Information Exposure vulnerability in Apple mac OS X and mac OS X Server
CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.
network
apple CWE-200
6.8
2008-03-18 CVE-2008-0047 Buffer Errors vulnerability in Cups 1.3.5
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.
network
apple cups CWE-119
critical
9.3
2008-03-18 CVE-2008-0997 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted PostScript Printer Description (PPD) file that is not properly handled when querying a network printer.
network
apple CWE-119
6.8
2008-03-18 CVE-2008-0057 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list.
network
apple CWE-189
6.8
2008-03-18 CVE-2008-0051 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.
local
apple CWE-189
6.9
2008-03-18 CVE-2008-0050 Information Exposure vulnerability in Apple mac OS X and mac OS X Server
CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.
network
low complexity
apple CWE-200
5.0
2008-03-18 CVE-2008-0049 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.
local
apple CWE-264
1.9
2008-03-18 CVE-2008-0048 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API.
network
apple CWE-119
6.8