Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2006-11-28 CVE-2006-6130 Stack Buffer Overflow vulnerability in Apple Mac OS X AppleTalk AIOCRegLocalZN IOCTL
Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.
local
low complexity
apple
4.9
2006-11-27 CVE-2006-6129 Integer Overflow vulnerability in Apple Mac OS X Mach-O Binary Loading
Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.
local
low complexity
apple
4.6
2006-11-27 CVE-2006-6127 Local Denial of Service vulnerability in Apple Mac OS X KQueue
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.
local
low complexity
apple
2.1
2006-11-27 CVE-2006-6126 Privilege Escalation vulnerability in Apple Mac OS X Mach-O Binary Loading
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.
local
low complexity
apple
2.1
2006-11-22 CVE-2006-6062 Remote Denial Of Service vulnerability in Apple Mac OS X UDIF Disk Image
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.
network
high complexity
apple
5.1
2006-11-22 CVE-2006-6061 Remote Denial Of Service vulnerability in Apple Mac OS X UDIF Disk Image
com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption.
network
apple
critical
9.3
2006-11-21 CVE-2006-6015 Remote Denial of Service vulnerability in Apple mac OS X 10.4
Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression.
network
low complexity
apple
5.0
2006-11-18 CVE-2006-4413 Remote Desktop Insecure Default Package Permission vulnerability in Apple Remote Desktop 2.0/2.1/3.0
Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages.
local
low complexity
apple
7.2
2006-11-04 CVE-2006-5710 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow.
network
low complexity
apple opendarwin CWE-119
7.5
2006-10-03 CVE-2006-4399 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, when such an operation is not actually supported, which could result in less secure password management than intended.
local
low complexity
apple
2.1