Show filters
131 Total Results
Displaying 121-130 of 131
Sort by:
Attacker Value
Unknown
CVE-2003-0877
Disclosure Date: November 03, 2003 (last updated February 22, 2025)
Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.
0
Attacker Value
Unknown
CVE-2003-0876
Disclosure Date: November 03, 2003 (last updated February 22, 2025)
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.
0
Attacker Value
Unknown
CVE-2003-0171
Disclosure Date: May 05, 2003 (last updated February 22, 2025)
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
0
Attacker Value
Unknown
CVE-2003-0198
Disclosure Date: May 05, 2003 (last updated February 22, 2025)
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
0
Attacker Value
Unknown
CVE-2002-2326
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.
0
Attacker Value
Unknown
CVE-2002-1265
Disclosure Date: November 12, 2002 (last updated February 22, 2025)
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
0
Attacker Value
Unknown
CVE-2002-0659
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
0
Attacker Value
Unknown
CVE-2002-0656
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
0
Attacker Value
Unknown
CVE-2002-0655
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2002-0676
Disclosure Date: July 11, 2002 (last updated February 22, 2025)
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.
0