Show filters
117 Total Results
Displaying 111-117 of 117
Sort by:
Attacker Value
Unknown
CVE-2010-1836
Disclosure Date: November 15, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2010-1820
Disclosure Date: September 21, 2010 (last updated October 04, 2023)
Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.
0
Attacker Value
Unknown
CVE-2010-1801
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2010-1802
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.
0
Attacker Value
Unknown
CVE-2010-1808
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
0
Attacker Value
Unknown
CVE-2010-1800
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.
0
Attacker Value
Unknown
CVE-2010-1119
Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.
0