Show filters
176 Total Results
Displaying 41-50 of 176
Sort by:
Attacker Value
Unknown
CVE-2011-3227
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
0
Attacker Value
Unknown
CVE-2011-0185
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.
0
Attacker Value
Unknown
CVE-2011-3214
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-3213
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.
0
Attacker Value
Unknown
CVE-2011-3222
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
0
Attacker Value
Unknown
CVE-2011-3422
Disclosure Date: September 12, 2011 (last updated October 04, 2023)
The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.
0
Attacker Value
Unknown
CVE-2011-0203
Disclosure Date: June 24, 2011 (last updated October 04, 2023)
Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.
0
Attacker Value
Unknown
CVE-2011-0200
Disclosure Date: June 24, 2011 (last updated October 04, 2023)
Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2011-0205
Disclosure Date: June 24, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.
0
Attacker Value
Unknown
CVE-2011-0201
Disclosure Date: June 24, 2011 (last updated October 04, 2023)
Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.
0