Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2010-06-11 CVE-2010-1388 Information Exposure vulnerability in Apple Safari and Webkit
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a crafted HTML document.
4.3
2010-06-11 CVE-2010-1385 Resource Management Errors vulnerability in Apple Safari
Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
network
apple microsoft CWE-399
critical
9.3
2010-06-11 CVE-2010-1384 Information Exposure vulnerability in Apple Safari
Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
4.3
2010-05-21 CVE-2010-0539 Numeric Errors vulnerability in Apple Java 1.5 and Java 1.6
Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted applet.
network
apple CWE-189
6.8
2010-05-21 CVE-2010-0538 Resource Management Errors vulnerability in Apple Java
Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted applet, related to the com.sun.medialib.mlib package.
network
apple CWE-399
6.8
2010-05-14 CVE-2010-1940 Credentials Management vulnerability in Apple Safari 4.0.5
Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests.
4.3
2010-05-13 CVE-2010-1939 Resource Management Errors vulnerability in Apple Safari 4.0.5
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.
network
high complexity
apple microsoft CWE-399
7.6
2010-05-06 CVE-2010-1729 Resource Management Errors vulnerability in Apple Safari and Webkit
WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.
4.3
2010-05-06 CVE-2010-1728 Resource Management Errors vulnerability in Opera Browser
Opera before 10.53 on Windows and Mac OS X does not properly handle a series of document modifications that occur asynchronously, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop, leading to attempted use of uninitialized memory.
network
opera apple microsoft CWE-399
critical
9.3
2010-04-27 CVE-2010-0105 Local Denial of Service vulnerability in Apple Mac OS X HFS Hard Links
The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.
local
low complexity
apple
4.9