Show filters
279 Total Results
Displaying 101-110 of 279
Sort by:
Attacker Value
Unknown

CVE-2008-2313

Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
0
Attacker Value
Unknown

CVE-2008-2314

Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2309

Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
0
Attacker Value
Unknown

CVE-2008-2311

Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.
0
Attacker Value
Unknown

CVE-2008-2310

Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
0
Attacker Value
Unknown

CVE-2008-2308

Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information.
0
Attacker Value
Unknown

CVE-2008-1030

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-1579

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog.
0
Attacker Value
Unknown

CVE-2008-1574

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-1036

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
0