Show filters
62 Total Results
Displaying 41-50 of 62
Sort by:
Attacker Value
Unknown

CVE-2009-1235

Disclosure Date: April 02, 2009 (last updated October 04, 2023)
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
0
Attacker Value
Unknown

CVE-2009-1238

Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.
0
Attacker Value
Unknown

CVE-2009-1237

Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.
0
Attacker Value
Unknown

CVE-2009-1236

Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.
0
Attacker Value
Unknown

CVE-2007-0729

Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
0
Attacker Value
Unknown

CVE-2006-4866

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
0
Attacker Value
Unknown

CVE-2006-1220

Disclosure Date: March 14, 2006 (last updated February 22, 2025)
Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2005-4504

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.
0
Attacker Value
Unknown

CVE-2005-2739

Disclosure Date: November 01, 2005 (last updated February 22, 2025)
Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out while the password is being viewed, which could allow attackers with physical access to obtain the password.
0
Attacker Value
Unknown

CVE-2005-2509

Disclosure Date: August 19, 2005 (last updated February 22, 2025)
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.
0