Vulnerabilities > Apple > MAC OS X > Critical

DATE CVE VULNERABILITY TITLE RISK
2014-04-29 CVE-2014-0515 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Flash Player
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
network
low complexity
adobe linux apple microsoft CWE-119
critical
10.0
2014-04-23 CVE-2014-1318 Improper Input Validation vulnerability in Apple mac OS X
The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.
network
low complexity
apple CWE-20
critical
10.0
2014-04-23 CVE-2014-1314 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox protection mechanism and execute arbitrary code via a crafted application.
network
low complexity
apple CWE-264
critical
10.0
2014-04-08 CVE-2014-0507 Buffer Errors vulnerability in Adobe Air, Adobe AIR SDK and Flash Player
Buffer overflow in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows attackers to execute arbitrary code via unspecified vectors.
network
adobe apple microsoft linux CWE-119
critical
9.3
2014-03-26 CVE-2014-1300 Memory Corruption vulnerability in Apple Safari 7.0.2
Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competition at CanSecWest 2014.
network
low complexity
apple
critical
10.0
2014-02-21 CVE-2014-0502 Resource Management Errors vulnerability in Adobe Air, Adobe AIR SDK and Flash Player
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
network
low complexity
adobe apple microsoft linux CWE-399
critical
10.0
2014-02-21 CVE-2014-0498 Buffer Errors vulnerability in Adobe Air, Adobe AIR SDK and Flash Player
Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
adobe apple microsoft linux CWE-119
critical
10.0
2014-02-05 CVE-2014-0497 Numeric Errors vulnerability in Adobe Flash Player
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
adobe linux apple microsoft CWE-189
critical
10.0
2014-01-15 CVE-2014-0496 Resource Management Errors vulnerability in Adobe Acrobat
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
adobe apple microsoft CWE-399
critical
10.0
2014-01-15 CVE-2014-0495 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat
Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0493.
network
low complexity
adobe apple microsoft CWE-119
critical
10.0