Show filters
151 Total Results
Displaying 111-120 of 151
Sort by:
Attacker Value
Unknown

CVE-2008-1027

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic.
0
Attacker Value
Unknown

CVE-2008-1578

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process.
0
Attacker Value
Unknown

CVE-2008-1032

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
0
Attacker Value
Unknown

CVE-2008-1577

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues."
0
Attacker Value
Unknown

CVE-2008-1573

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2008-1571

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
0
Attacker Value
Unknown

CVE-2008-1028

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.
0
Attacker Value
Unknown

CVE-2008-1031

Disclosure Date: June 02, 2008 (last updated October 04, 2023)
CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable.
0
Attacker Value
Unknown

CVE-2008-0059

Disclosure Date: March 18, 2008 (last updated October 04, 2023)
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
0
Attacker Value
Unknown

CVE-2008-0990

Disclosure Date: March 18, 2008 (last updated October 04, 2023)
notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications.
0