Vulnerabilities > Apple > MAC OS X

DATE CVE VULNERABILITY TITLE RISK
2005-06-13 CVE-2005-1473 Unspecified vulnerability in Apple mac OS X 10.4.1
SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.
local
low complexity
apple
4.6
2005-06-08 CVE-2005-1728 Unspecified vulnerability in Apple mac OS X 10.4/10.4.1
MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.
local
low complexity
apple
4.6
2005-05-19 CVE-2005-1472 Unspecified vulnerability in Apple mac OS X 10.4.1
Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.
local
low complexity
apple
2.1
2005-05-19 CVE-2005-1260 Resource Exhaustion vulnerability in multiple products
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
network
low complexity
bzip canonical debian apple CWE-400
5.0
2005-05-17 CVE-2005-1307 Local Privilege Escalation vulnerability in Adobe Version Cue
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
local
low complexity
adobe apple
7.2
2005-05-12 CVE-2005-0974 Unspecified vulnerability in Apple mac OS X
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
local
low complexity
apple
7.2
2005-05-12 CVE-2005-0973 Unspecified vulnerability in Apple mac OS X
Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.
local
low complexity
apple
2.1
2005-05-12 CVE-2005-0972 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
local
low complexity
apple
7.2
2005-05-12 CVE-2005-0971 Unspecified vulnerability in Apple mac OS X
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
local
low complexity
apple
4.6
2005-05-12 CVE-2005-0969 Unspecified vulnerability in Apple mac OS X
Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.
local
low complexity
apple
4.6