Vulnerabilities > Apple > High

DATE CVE VULNERABILITY TITLE RISK
2004-07-27 CVE-2004-0720 Unspecified vulnerability in Apple Safari 1.2.2
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
network
low complexity
apple
7.5
2004-07-07 CVE-2004-0486 Remote Code Execution vulnerability in Apple Mac OS X Help Protocol
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.
network
high complexity
apple
7.6
2004-05-04 CVE-2004-0383 Unspecified vulnerability in Apple mac OS X 10.2.8/10.3.3
Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."
local
low complexity
apple
7.2
2004-05-04 CVE-2004-0382 Unspecified vulnerability in Apple mac OS X 10.2.8/10.3.3
Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.
local
low complexity
apple
7.2
2004-04-15 CVE-2003-0514 Unspecified vulnerability in Apple Safari 1.0/1.1
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g.
network
low complexity
apple
7.5
2004-03-29 CVE-2003-1011 Local Root Privilege Elevation vulnerability in MacOS X
Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.
local
low complexity
apple
7.2
2004-03-29 CVE-2003-1006 Local Buffer Overflow vulnerability in MacOSX CD9660.Util Probe For Mounting Argument
Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.
local
low complexity
apple
7.2
2004-03-29 CVE-2003-0601 Unspecified vulnerability in Apple mac OS X Server
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.
network
low complexity
apple
7.5
2004-03-15 CVE-2004-0167 Remote vulnerability in Multiple Apple Mac OS X Local And
DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.
network
low complexity
apple
7.5
2004-02-03 CVE-2004-1082 mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
network
low complexity
apache apple avaya hp ibm openbsd sco sun
7.5