Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-01-24 CVE-2007-0023 Local Privilege Escalation vulnerability in Apple mac OS X 10.4.8
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.
local
apple
6.9
2007-01-23 CVE-2007-0430 Denial-Of-Service vulnerability in Mac OS X
The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.
local
low complexity
apple
4.9
2007-01-18 CVE-2007-0345 Local Security vulnerability in Apple mac OS X 10.4.8
The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.
local
low complexity
apple
6.8
2007-01-18 CVE-2007-0342 Resource Management Errors vulnerability in multiple products
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
4.3
2007-01-17 CVE-2007-0267 Resource Management Errors vulnerability in multiple products
The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function.
local
low complexity
apple freebsd CWE-399
6.6
2007-01-11 CVE-2007-0197 Improper Input Validation vulnerability in Apple mac OS X 10.4.6/10.4.8
Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.
network
apple CWE-20
6.8
2007-01-09 CVE-2007-0102 Improper Input Validation vulnerability in Apple Preview 3.0.8
The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
network
apple CWE-20
6.8
2007-01-05 CVE-2007-0059 Remote Security vulnerability in QuickTime Player
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.
network
apple
6.8
2007-01-01 CVE-2007-0015 Remote Buffer Overflow vulnerability in Apple Quicktime 7.1.3
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
network
apple
6.8
2006-12-07 CVE-2006-6353 Remote Archive File vulnerability in Apple BOMArchiveHelper
Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the "iSec Partners FileP fuzzer".
network
low complexity
apple
5.0