Vulnerabilities > Apple > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-06-12 CVE-2007-3186 Permissions, Privileges, and Access Controls vulnerability in Apple Safari
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.
network
apple CWE-264
critical
9.3
2007-06-04 CVE-2007-2387 Remote Privilege Escalation vulnerability in Apple Xserve Lights-Out Management Firmware0
Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardware does not require a password for remote access to IPMI, which allows remote attackers to gain administrative access via unspecified requests with ipmitool.
network
low complexity
apple
critical
10.0
2007-05-29 CVE-2007-2388 Permissions, Privileges, and Access Controls vulnerability in Apple Quicktime 7.1.6
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
network
apple microsoft CWE-264
critical
9.3
2007-05-24 CVE-2007-2390 Multiple Security vulnerability in Apple mac OS X 10.3.9/10.4.9
Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
network
low complexity
apple
critical
10.0
2007-05-24 CVE-2007-2386 Multiple Security vulnerability in Apple Mac OS X 2007-005
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
network
low complexity
apple
critical
9.4
2007-05-24 CVE-2007-0750 Multiple Security vulnerability in Apple Mac OS X 2007-005
Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.
network
apple
critical
9.3
2007-05-24 CVE-2007-2843 Information Disclosure vulnerability in Apple Safari 2.0.4
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.
network
low complexity
apple
critical
10.0
2007-05-17 CVE-2007-2736 Remote File Include vulnerability in Achievo 1.1.0
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
network
low complexity
apple hp ibm linux microsoft santa-cruz-operation sun windriver achievo
critical
10.0
2007-05-14 CVE-2007-0754 Buffer Overflow vulnerability in Apple QuickTime MOV File STSD Heap
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie.
network
apple
critical
9.3
2007-05-13 CVE-2007-0749 Remote Buffer Overflow vulnerability in Apple Darwin Streaming Server
Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request.
network
low complexity
apple
critical
10.0