Vulnerabilities > Apple > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-10-10 CVE-2008-4211 Numeric Errors vulnerability in Apple Iphone OS, mac OS X and mac OS X Server
Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
network
low complexity
apple CWE-189
critical
10.0
2008-10-10 CVE-2008-3647 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.
network
apple CWE-119
critical
9.3
2008-10-10 CVE-2008-3642 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
network
apple CWE-119
critical
9.3
2008-10-10 CVE-2008-3641 Resource Management Errors vulnerability in Apple Cups
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
network
low complexity
apple CWE-399
critical
10.0
2008-09-26 CVE-2008-3638 Code Injection vulnerability in Apple mac OS X and mac OS X Server
Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.
network
apple CWE-94
critical
9.3
2008-09-18 CVE-2008-4116 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes and Quicktime
Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that leads to a heap-based buffer overflow.
network
apple CWE-119
critical
9.3
2008-09-16 CVE-2008-3621 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving H.264 encoded media.
network
apple CWE-399
critical
9.3
2008-09-16 CVE-2008-3618 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended.
network
low complexity
apple CWE-264
critical
9.0
2008-09-16 CVE-2008-3616 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
network
low complexity
apple CWE-189
critical
10.0
2008-09-16 CVE-2008-3608 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
network
apple CWE-399
critical
9.3