Vulnerabilities > Apple > MAC OS X > High

DATE CVE VULNERABILITY TITLE RISK
2009-02-13 CVE-2009-0017 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.
local
low complexity
apple CWE-119
7.2
2009-02-13 CVE-2009-0011 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file.
local
low complexity
apple CWE-264
7.2
2009-01-15 CVE-2009-0123 Information Exposure vulnerability in Apple Safari
Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.
7.1
2008-12-17 CVE-2008-4236 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file.
network
apple CWE-399
7.1
2008-12-17 CVE-2008-4224 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafted ISO file.
network
apple CWE-20
7.1
2008-12-17 CVE-2008-4222 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinite loop) via a crafted TCP packet.
network
apple CWE-399
7.1
2008-12-17 CVE-2008-4218 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call to (1) i386_set_ldt or (2) i386_get_ldt.
local
low complexity
apple CWE-189
7.2
2008-11-21 CVE-2008-5183 NULL Pointer Dereference vulnerability in multiple products
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference.
network
low complexity
apple opensuse debian CWE-476
7.5
2008-10-10 CVE-2008-3645 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Networking component) in Mac OS X 10.4.11 and 10.5.5 allows local users to execute arbitrary code via unknown vectors.
local
low complexity
apple CWE-119
7.2
2008-10-10 CVE-2008-3643 Multiple Security vulnerability in RETIRED: Apple Mac OS X 2008-007
Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a denial of service (continuous termination and restart) via a crafted Desktop file that generates an error when producing its icon, related to an "error recovery issue."
network
low complexity
apple
7.8