Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2005-01-10 CVE-2004-1122 Unspecified vulnerability in Apple Safari 1.2.3
Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314.
network
low complexity
apple
7.5
2004-12-31 CVE-2004-2687 Configuration vulnerability in multiple products
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
network
apple samba CWE-16
critical
9.3
2004-12-31 CVE-2004-2154 Improper Handling of Case Sensitivity vulnerability in multiple products
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
network
low complexity
apple canonical CWE-178
critical
9.8
2004-12-31 CVE-2004-1832 Remote Buffer Overflow vulnerability in Apple mac OS X Server 10.3
Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.
network
low complexity
apple
5.0
2004-12-31 CVE-2004-0825 Denial of Service vulnerability in Apple mac OS X Server 10.2.8/10.3.4/10.3.5
QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to cause a denial of service (application deadlock) via a certain sequence of operations.
network
low complexity
apple
5.0
2004-12-31 CVE-2004-0824 Symbolic Link vulnerability in Apple PPPDialer Insecure Log File Creation
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.
local
low complexity
apple
2.1
2004-12-31 CVE-2004-0821 Unspecified vulnerability in Apple mac OS X and mac OS X Server
The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.
local
low complexity
apple
7.2
2004-12-31 CVE-2004-0429 Remote Security vulnerability in Apple mac OS X 10.2.8/10.3.3
Unknown vulnerability related to "the handling of large requests" in RAdmin for Apple Mac OS X 10.3.3 and Mac OS X 10.2.8 may allow attackers to have unknown impact via unknown attack vectors.
network
low complexity
apple
critical
10.0
2004-12-31 CVE-2004-0090 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.
network
low complexity
apple
critical
10.0
2004-12-23 CVE-2004-0873 Unspecified vulnerability in Apple Ichat and Ichat AV
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.
network
low complexity
apple
7.5