Show filters
157 Total Results
Displaying 121-130 of 157
Sort by:
Attacker Value
Unknown
CVE-2006-4387
Disclosure Date: October 03, 2006 (last updated October 04, 2023)
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows the user to manage WebObjects applications.
0
Attacker Value
Unknown
CVE-2006-4397
Disclosure Date: October 03, 2006 (last updated October 04, 2023)
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access to the original user's Kerberos tickets.
0
Attacker Value
Unknown
CVE-2006-4392
Disclosure Date: October 03, 2006 (last updated October 04, 2023)
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.
0
Attacker Value
Unknown
CVE-2006-4393
Disclosure Date: October 03, 2006 (last updated October 04, 2023)
Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.
0
Attacker Value
Unknown
CVE-2006-4390
Disclosure Date: October 03, 2006 (last updated October 04, 2023)
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site's identity cannot be trusted.
0
Attacker Value
Unknown
CVE-2006-4395
Disclosure Date: October 03, 2006 (last updated October 04, 2023)
Unspecified vulnerability in QuickDraw Manager in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows context-dependent attackers to cause a denial of service ("memory corruption" and crash) via a crafted PICT image that is not properly handled by a certain "unsupported QuickDraw operation."
0
Attacker Value
Unknown
CVE-2006-4866
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
0
Attacker Value
Unknown
CVE-2006-3946
Disclosure Date: July 31, 2006 (last updated October 04, 2023)
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer overflow, as originally reported for the KHTMLParser::popOneBlock function in Apple Safari 2.0.4 using Javascript that changes document.body.innerHTML within a DIV tag.
0
Attacker Value
Unknown
CVE-2006-1470
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.
0
Attacker Value
Unknown
CVE-2006-1469
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.
0