Show filters
377 Total Results
Displaying 221-230 of 377
Sort by:
Attacker Value
Unknown

CVE-2007-0355

Disclosure Date: January 19, 2007 (last updated October 04, 2023)
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.
0
Attacker Value
Unknown

CVE-2007-0342

Disclosure Date: January 18, 2007 (last updated October 04, 2023)
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
0
Attacker Value
Unknown

CVE-2007-0345

Disclosure Date: January 18, 2007 (last updated October 04, 2023)
The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.
0
Attacker Value
Unknown

CVE-2007-0318

Disclosure Date: January 18, 2007 (last updated October 04, 2023)
The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.
0
Attacker Value
Unknown

CVE-2007-0299

Disclosure Date: January 17, 2007 (last updated October 04, 2023)
Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.
0
Attacker Value
Unknown

CVE-2007-0267

Disclosure Date: January 17, 2007 (last updated October 04, 2023)
The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function. NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries.
0
Attacker Value
Unknown

CVE-2007-0236

Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2007-0229

Disclosure Date: January 13, 2007 (last updated October 04, 2023)
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.
0
Attacker Value
Unknown

CVE-2007-0197

Disclosure Date: January 11, 2007 (last updated October 04, 2023)
Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.
0
Attacker Value
Unknown

CVE-2007-0117

Disclosure Date: January 09, 2007 (last updated October 04, 2023)
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.
0