Show filters
166 Total Results
Displaying 141-150 of 166
Sort by:
Attacker Value
Unknown

CVE-2010-0521

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.
0
Attacker Value
Unknown

CVE-2010-0524

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.
0
Attacker Value
Unknown

CVE-2010-0537

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a crafted share name.
0
Attacker Value
Unknown

CVE-2010-0500

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."
0
Attacker Value
Unknown

CVE-2010-0063

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url extensions.
0
Attacker Value
Unknown

CVE-2010-0062

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.
0
Attacker Value
Unknown

CVE-2010-0498

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-0507

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PEF image.
0
Attacker Value
Unknown

CVE-2010-0502

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform logging for all types of messages, which might allow remote attackers to avoid message auditing via an unspecified selection of message type.
0
Attacker Value
Unknown

CVE-2010-0518

Disclosure Date: March 30, 2010 (last updated October 04, 2023)
QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with Sorenson encoding.
0