Vulnerabilities > Apple > MAC OS X

DATE CVE VULNERABILITY TITLE RISK
2005-08-19 CVE-2005-2506 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.
network
low complexity
apple
5.0
2005-08-19 CVE-2005-2505 Unspecified vulnerability in Apple mac OS X 10.3.9
Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.
network
low complexity
apple
7.5
2005-08-19 CVE-2005-2504 Unspecified vulnerability in Apple mac OS X and mac OS X Server
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.
local
low complexity
apple
7.2
2005-08-19 CVE-2005-2503 Unspecified vulnerability in Apple mac OS X and mac OS X Server
AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
local
low complexity
apple
4.6
2005-08-19 CVE-2005-2502 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.
network
high complexity
apple
5.1
2005-08-19 CVE-2005-2501 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
network
high complexity
apple
7.6
2005-07-18 CVE-2005-1689 Double Free vulnerability in multiple products
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
network
low complexity
mit apple debian CWE-415
critical
9.8
2005-06-16 CVE-2005-1722 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.
local
low complexity
apple
7.2
2005-06-13 CVE-2005-1933 Remote Security vulnerability in Apple mac OS X 10.4
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.
network
low complexity
apple
7.5
2005-06-13 CVE-2005-1474 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
network
low complexity
apple
7.5