Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2008-12-17 CVE-2008-4218 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call to (1) i386_set_ldt or (2) i386_get_ldt.
local
low complexity
apple CWE-189
7.2
2008-12-17 CVE-2008-4217 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO archive, leading to a stack-based buffer overflow.
network
apple CWE-189
critical
9.3
2008-12-10 CVE-2008-5406 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes and Quicktime
Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."
network
apple CWE-119
critical
9.3
2008-12-08 CVE-2008-5377 Link Following vulnerability in Apple Cups 1.3.8
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
local
apple CWE-59
6.9
2008-12-03 CVE-2008-5315 Path Traversal vulnerability in Apple Iphone Configuration web Utility 1.0
Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
apple microsoft CWE-22
7.8
2008-12-01 CVE-2008-5286 Numeric Errors vulnerability in Apple Cups
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
network
low complexity
apple CWE-189
7.5
2008-11-25 CVE-2008-4233 Unspecified vulnerability in Apple Iphone OS and Safari
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.
network
high complexity
apple
2.6
2008-11-25 CVE-2008-4232 Unspecified vulnerability in Apple Iphone OS and Safari
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
network
low complexity
apple
5.0
2008-11-25 CVE-2008-4231 Resource Management Errors vulnerability in Apple Iphone OS and Safari
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
network
apple CWE-399
critical
9.3
2008-11-25 CVE-2008-4230 Information Exposure vulnerability in Apple Iphone OS
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by reading these messages.
local
apple CWE-200
1.9