Show filters
156 Total Results
Displaying 111-120 of 156
Sort by:
Attacker Value
Unknown

CVE-2008-2330

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
0
Attacker Value
Unknown

CVE-2008-2331

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.
0
Attacker Value
Unknown

CVE-2008-3616

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
0
Attacker Value
Unknown

CVE-2008-2305

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."
0
Attacker Value
Unknown

CVE-2008-3609

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file.
0
Attacker Value
Unknown

CVE-2008-2332

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
0
Attacker Value
Unknown

CVE-2008-3618

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended.
0
Attacker Value
Unknown

CVE-2008-3610

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
0
Attacker Value
Unknown

CVE-2008-3608

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
0
Attacker Value
Unknown

CVE-2008-2329

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows attackers to enumerate user names via wildcard characters in the Login Window.
0