Show filters
377 Total Results
Displaying 181-190 of 377
Sort by:
Attacker Value
Unknown
CVE-2007-2401
Disclosure Date: June 25, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2007-2399
Disclosure Date: June 25, 2007 (last updated October 04, 2023)
WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2007-2390
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
0
Attacker Value
Unknown
CVE-2007-0750
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2007-0752
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.
0
Attacker Value
Unknown
CVE-2007-0753
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
0
Attacker Value
Unknown
CVE-2007-0751
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.
0
Attacker Value
Unknown
CVE-2007-0740
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Alias Manager in Apple Mac OS X 10.3.9 and 10.4.9 does not display files with the same name in mounted disk images that have the same name, which might allow user-assisted attackers to trick a user into executing malicious files.
0
Attacker Value
Unknown
CVE-2007-2386
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
0
Attacker Value
Unknown
CVE-2007-0745
Disclosure Date: May 02, 2007 (last updated October 04, 2023)
The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.
0