Show filters
191 Total Results
Displaying 121-130 of 191
Sort by:
Attacker Value
Unknown

CVE-2010-1836

Disclosure Date: November 15, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
0
Attacker Value
Unknown

CVE-2010-1820

Disclosure Date: September 21, 2010 (last updated October 04, 2023)
Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.
0
Attacker Value
Unknown

CVE-2010-1801

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.
0
Attacker Value
Unknown

CVE-2010-1802

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.
0
Attacker Value
Unknown

CVE-2010-1808

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
0
Attacker Value
Unknown

CVE-2010-1800

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.
0
Attacker Value
Unknown

CVE-2010-0543

Disclosure Date: June 17, 2010 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.5.8, and 10.6 before 10.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with MPEG2 encoding.
0
Attacker Value
Unknown

CVE-2010-1373

Disclosure Date: June 17, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted help: URL, related to "URL parameters in HTML content."
0
Attacker Value
Unknown

CVE-2010-1382

Disclosure Date: June 17, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field.
0
Attacker Value
Unknown

CVE-2010-1377

Disclosure Date: June 17, 2010 (last updated October 04, 2023)
Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors.
0