Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2005-12-08 CVE-2005-4092 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes and Quicktime
Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and possibly other vectors involving media files.
network
low complexity
apple CWE-119
7.5
2005-12-01 CVE-2005-3705 Multiple vulnerability in RETIRED: Apple Mac OS X Security Update 2005-009
Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers to execute arbitrary code via unknown attack vectors.
network
low complexity
apple
7.5
2005-12-01 CVE-2005-3704 Multiple vulnerability in RETIRED: Apple Mac OS X Security Update 2005-009
System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as newline (NL).
network
low complexity
apple
5.0
2005-12-01 CVE-2005-3702 Multiple vulnerability in RETIRED: Apple Mac OS X Security Update 2005-009
Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be downloaded to locations outside the download directory via a long file name.
network
low complexity
apple
5.0
2005-12-01 CVE-2005-3701 Multiple vulnerability in Apple mac OS X Server 10.3.9/10.4.3
Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users to gain privileges via unknown attack vectors.
local
low complexity
apple
7.2
2005-12-01 CVE-2005-3700 Multiple vulnerability in RETIRED: Apple Mac OS X Security Update 2005-009
Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown attack vectors.
local
low complexity
apple
4.6
2005-12-01 CVE-2005-2757 Multiple vulnerability in RETIRED: Apple Mac OS X Security Update 2005-009
Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving "validation of URLs."
network
low complexity
apple
7.5
2005-11-29 CVE-2005-3897 Denial-Of-Service vulnerability in Apple Safari 2.0.2
Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function.
network
low complexity
apple
7.8
2005-11-18 CVE-2005-2938 Permissions, Privileges, and Access Controls vulnerability in Apple Itunes 4.7.1.30/5.0
Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.
local
low complexity
apple CWE-264
7.2
2005-11-05 CVE-2005-2756 Remote Buffer Overflow vulnerability in Apple QuickTime Compressed PICT Data
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
network
high complexity
apple
5.1