Vulnerabilities > Apple > High

DATE CVE VULNERABILITY TITLE RISK
2004-08-18 CVE-2004-0518 Remote Security vulnerability in Apple Mac OS X Server
Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.
network
low complexity
apple
7.5
2004-08-18 CVE-2004-0514 Security vulnerability in Apple Mac OS X
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."
local
low complexity
apple
7.2
2004-08-06 CVE-2004-0538 Unspecified vulnerability in Apple mac OS X and mac OS X Server
LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.
network
low complexity
apple
7.5
2004-07-27 CVE-2004-0720 Unspecified vulnerability in Apple Safari 1.2.2
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
network
low complexity
apple
7.5
2004-07-07 CVE-2004-0486 Remote Code Execution vulnerability in Apple Mac OS X Help Protocol
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.
network
high complexity
apple
7.6
2004-05-04 CVE-2004-0383 Unspecified vulnerability in Apple mac OS X 10.2.8/10.3.3
Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."
local
low complexity
apple
7.2
2004-05-04 CVE-2004-0382 Unspecified vulnerability in Apple mac OS X 10.2.8/10.3.3
Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.
local
low complexity
apple
7.2
2004-04-15 CVE-2003-0514 Unspecified vulnerability in Apple Safari 1.0/1.1
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g.
network
low complexity
apple
7.5
2004-03-29 CVE-2003-1011 Local Root Privilege Elevation vulnerability in MacOS X
Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.
local
low complexity
apple
7.2
2004-03-29 CVE-2003-1006 Local Buffer Overflow vulnerability in MacOSX CD9660.Util Probe For Mounting Argument
Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.
local
low complexity
apple
7.2