Vulnerabilities > Apple > MAC OS X > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-04-24 | CVE-2007-0742 | Multiple Security vulnerability in Apple Mac OS X 2007-004 The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information. | 7.8 |
2007-04-24 | CVE-2007-0741 | Multiple Security vulnerability in Apple Mac OS X 2007-004 Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets. | 7.5 |
2007-04-24 | CVE-2007-0732 | Multiple Security vulnerability in Apple Mac OS X 2007-004 Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port." The vendor has addressed this issue through Mac OS software updates. | 7.2 |
2007-04-24 | CVE-2007-0729 | Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X, mac OS X Preview.App and mac OS X Server Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables. | 7.2 |
2007-04-24 | CVE-2007-0725 | Multiple Security vulnerability in Apple Mac OS X 2007-004 Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands." | 7.2 |
2007-04-11 | CVE-2007-1279 | Local Privilege Escalation vulnerability in Adobe Bridge 1.0.3 Unspecified vulnerability in the installer for Adobe Bridge 1.0.3 update for Apple OS X, when patching with desktop management tools, allows local users to gain privileges via unspecified vectors during installation of the update by a different user who has administrative privileges. | 7.2 |
2007-03-13 | CVE-2007-0723 | Applications Multiple vulnerability in Apple Mac OS X Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors. network apple | 8.5 |
2007-03-02 | CVE-2007-1222 | Local Security vulnerability in Parallels Desktop for Mac OS X Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory. | 7.2 |
2007-02-23 | CVE-2006-7034 | SQL-Injection vulnerability in Super Link Exchange Script Super Link Exchange Script 1.0 SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter. network low complexity apple hp ibm linux microsoft santa-cruz-operation sun windriver super-link-exchange-script | 7.5 |
2007-02-22 | CVE-2007-1071 | Integer Overflow vulnerability in Apple Mac OS X ImageIO GIF Image Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression. | 7.8 |