Vulnerabilities > Apple > MAC OS X > Low

DATE CVE VULNERABILITY TITLE RISK
2006-03-03 CVE-2006-0389 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.
network
high complexity
apple
2.6
2006-03-03 CVE-2006-0391 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.
local
low complexity
apple
1.7
2006-02-14 CVE-2006-0382 Local Denial Of Service vulnerability in Apple mac OS X 10.4.5
Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.
local
low complexity
apple
2.1
2005-12-31 CVE-2005-0985 Denial-Of-Service vulnerability in Apple Mac OS X
Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) driver.
local
low complexity
apple
2.1
2005-12-31 CVE-2005-3782 Denial-Of-Service vulnerability in Apple Mac OS X Server
Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to bypass login and reboot the system by entering ">restart", ">power", or ">shutdown" sequences after the username.
local
low complexity
apple
2.1
2005-11-01 CVE-2005-2739 Local vulnerability in Apple Mac OS X Security Update 2005-10-31
Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out while the password is being viewed, which could allow attackers with physical access to obtain the password.
local
low complexity
apple
2.1
2005-11-01 CVE-2005-2749 Local vulnerability in Apple Mac OS X Security Update 2005-10-31
Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder to misrepresent file and group ownership information.
local
low complexity
apple
2.1
2005-11-01 CVE-2005-2751 Local vulnerability in Apple Mac OS X Security Update 2005-10-31
memberd in Mac OS X 10.4 up to 10.4.2, in certain situations, does not quickly synchronize access control checks with changes in group membership, which could allow users to access files and other resources after they have been removed from a group.
local
low complexity
apple
2.1
2005-11-01 CVE-2005-2752 Information Exposure vulnerability in Apple mac OS X and mac OS X Server
An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability than CVE-2005-1126 and CVE-2005-1406.
local
low complexity
apple CWE-200
2.1
2005-10-25 CVE-2005-2748 Unspecified vulnerability in Apple mac OS X and mac OS X Server
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application.
local
low complexity
apple
2.1