Show filters
152 Total Results
Displaying 21-30 of 152
Sort by:
Attacker Value
Unknown
CVE-2008-7303
Disclosure Date: November 15, 2011 (last updated October 04, 2023)
The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's execution of a script file, a related issue to CVE-2011-1516.
0
Attacker Value
Unknown
CVE-2011-1516
Disclosure Date: November 15, 2011 (last updated October 04, 2023)
The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.
0
Attacker Value
Unknown
CVE-2011-0229
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access.
0
Attacker Value
Unknown
CVE-2011-3217
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.
0
Attacker Value
Unknown
CVE-2011-3221
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.
0
Attacker Value
Unknown
CVE-2011-3220
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
0
Attacker Value
Unknown
CVE-2011-3224
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.
0
Attacker Value
Unknown
CVE-2011-0230
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-0224
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.
0
Attacker Value
Unknown
CVE-2011-3223
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.
0