Show filters
166 Total Results
Displaying 161-166 of 166
Sort by:
Attacker Value
Unknown
CVE-2010-0513
Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PostScript document.
0
Attacker Value
Unknown
CVE-2010-0510
Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users to obtain login access via an expired password.
0
Attacker Value
Unknown
CVE-2010-0059
Disclosure Date: March 30, 2010 (last updated October 04, 2023)
CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields, related to QDCA.
0
Attacker Value
Unknown
CVE-2010-0533
Disclosure Date: March 30, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and modify files in that directory, via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-0057
Disclosure Date: March 30, 2010 (last updated October 04, 2023)
AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request.
0
Attacker Value
Unknown
CVE-2010-1119
Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.
0