Vulnerabilities > Apple > High

DATE CVE VULNERABILITY TITLE RISK
2009-11-10 CVE-2009-2828 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
network
low complexity
apple CWE-399
7.5
2009-10-16 CVE-2009-3282 Numeric Errors vulnerability in VMWare Fusion
Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors.
network
low complexity
vmware apple CWE-189
7.8
2009-10-16 CVE-2009-3281 Permissions, Privileges, and Access Controls vulnerability in VMWare Fusion
The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.
local
low complexity
vmware apple CWE-264
7.2
2009-09-29 CVE-2009-3455 Cryptographic Issues vulnerability in Apple Safari
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
network
low complexity
apple CWE-310
7.5
2009-09-21 CVE-2009-3273 Cryptographic Issues vulnerability in Apple Iphone OS
iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.
network
low complexity
apple CWE-310
7.5
2009-09-14 CVE-2009-2807 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to gain privileges via unspecified vectors.
local
low complexity
apple CWE-119
7.2
2009-09-10 CVE-2009-2815 Resource Management Errors vulnerability in Apple Iphone OS
The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer dereference and service interruption) via a crafted SMS message.
network
low complexity
apple CWE-399
7.8
2009-09-10 CVE-2009-2795 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to "command parsing."
local
low complexity
apple CWE-119
7.2
2009-08-12 CVE-2009-2200 Information Exposure vulnerability in Apple Safari
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
7.1
2009-08-06 CVE-2009-2192 Credentials Management vulnerability in Apple mac OS X and mac OS X Server
MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for attackers to hijack a MobileMe session via unspecified vectors, related to a "logic issue."
network
low complexity
apple CWE-255
7.5