Show filters
143 Total Results
Displaying 111-120 of 143
Sort by:
Attacker Value
Unknown
CVE-2007-0614
Disclosure Date: January 31, 2007 (last updated October 04, 2023)
The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.
0
Attacker Value
Unknown
CVE-2007-0467
Disclosure Date: January 31, 2007 (last updated October 04, 2023)
crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.
0
Attacker Value
Unknown
CVE-2007-0465
Disclosure Date: January 31, 2007 (last updated October 04, 2023)
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
0
Attacker Value
Unknown
CVE-2007-0588
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.
0
Attacker Value
Unknown
CVE-2007-0462
Disclosure Date: January 26, 2007 (last updated October 04, 2023)
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.
0
Attacker Value
Unknown
CVE-2007-0023
Disclosure Date: January 24, 2007 (last updated October 04, 2023)
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.
0
Attacker Value
Unknown
CVE-2007-0022
Disclosure Date: January 23, 2007 (last updated October 04, 2023)
Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.
0
Attacker Value
Unknown
CVE-2007-0355
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.
0
Attacker Value
Unknown
CVE-2007-0342
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
0
Attacker Value
Unknown
CVE-2007-0345
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.
0