Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2006-10-03 CVE-2006-4397 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access to the original user's Kerberos tickets.
local
low complexity
apple
4.6
2006-10-03 CVE-2006-4395 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
Unspecified vulnerability in QuickDraw Manager in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows context-dependent attackers to cause a denial of service ("memory corruption" and crash) via a crafted PICT image that is not properly handled by a certain "unsupported QuickDraw operation."
network
high complexity
apple
5.1
2006-10-03 CVE-2006-4394 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without GUIds to bypass service access controls and log into the system using loginwindow via unknown vectors.
network
low complexity
apple
7.5
2006-10-03 CVE-2006-4393 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.
local
high complexity
apple
3.7
2006-10-03 CVE-2006-4392 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.
local
low complexity
apple next
7.2
2006-10-03 CVE-2006-4391 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
Buffer overflow in Apple ImageIO on Apple Mac OS X 10.4 through 10.4.7 allows remote attackers to execute arbitrary code via a malformed JPEG2000 image.
network
high complexity
apple
5.1
2006-10-03 CVE-2006-4390 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site's identity cannot be trusted.
network
high complexity
apple
2.6
2006-10-03 CVE-2006-4387 Multiple Security vulnerability in Apple Mac OS X Pre 10.4.8
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows the user to manage WebObjects applications.
local
low complexity
apple
4.6
2006-09-27 CVE-2006-5051 Double Free vulnerability in multiple products
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
network
high complexity
openbsd debian apple CWE-415
8.1
2006-09-25 CVE-2006-4965 Code Injection vulnerability in Apple Quicktime 7.1.3
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain.
network
low complexity
apple CWE-94
5.0