Show filters
192 Total Results
Displaying 31-40 of 192
Sort by:
Attacker Value
Unknown

CVE-2011-3227

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
0
Attacker Value
Unknown

CVE-2011-3214

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-3213

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.
0
Attacker Value
Unknown

CVE-2011-3222

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
0
Attacker Value
Unknown

CVE-2009-2818

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force attack (aka dictionary attack).
0
Attacker Value
Unknown

CVE-2009-2834

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) Bluetooth keyboard via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-2832

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a "CWD command line tool."
0
Attacker Value
Unknown

CVE-2009-2825

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
0
Attacker Value
Unknown

CVE-2009-2808

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-middle attackers to send a crafted help:runscript link, and thereby execute arbitrary code, via a spoofed response.
0
Attacker Value
Unknown

CVE-2009-2835

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors.
0