Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2007-07-27 CVE-2007-4045 The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.
network
low complexity
apple fedoraproject
5.0
2007-07-23 CVE-2007-3944 Buffer Errors vulnerability in Apple Iphone OS, Safari and Webkit
Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via certain JavaScript regular expressions.
network
apple CWE-119
critical
9.3
2007-07-17 CVE-2007-3828 Remote Code Execution vulnerability in Apple Mac OS X mDNSResponder Variant
Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbitrary code via unspecified vectors, a related issue to CVE-2007-2386.
network
low complexity
apple
critical
10.0
2007-07-16 CVE-2007-3798 Unchecked Return Value vulnerability in multiple products
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
network
low complexity
tcpdump canonical debian slackware freebsd apple CWE-252
critical
9.8
2007-07-15 CVE-2007-2402 Information Exposure vulnerability in Apple Quicktime
QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.
network
apple CWE-200
4.3
2007-07-15 CVE-2007-2397 Code Execution vulnerability in Apple QuickTime
QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets.
network
apple
critical
9.3
2007-07-15 CVE-2007-2396 Code Execution vulnerability in Apple QuickTime
The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets.
network
apple
critical
9.3
2007-07-15 CVE-2007-2394 Code Execution vulnerability in Apple QuickTime
Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.
network
apple
critical
9.3
2007-07-15 CVE-2007-2393 Code Execution vulnerability in Apple QuickTime
The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution.
network
apple
critical
9.3
2007-07-15 CVE-2007-2392 Code Execution vulnerability in Apple QuickTime
Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption.
network
apple
critical
9.3