Show filters
102 Total Results
Displaying 31-40 of 102
Sort by:
Attacker Value
Unknown

CVE-2011-3218

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
0
Attacker Value
Unknown

CVE-2011-3216

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.
0
Attacker Value
Unknown

CVE-2011-0231

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."
0
Attacker Value
Unknown

CVE-2011-3227

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
0
Attacker Value
Unknown

CVE-2011-3214

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-3213

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.
0
Attacker Value
Unknown

CVE-2011-3222

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
0
Attacker Value
Unknown

CVE-2009-2818

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force attack (aka dictionary attack).
0
Attacker Value
Unknown

CVE-2009-2834

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) Bluetooth keyboard via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-2832

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a "CWD command line tool."
0