Show filters
114 Total Results
Displaying 41-50 of 114
Sort by:
Attacker Value
Unknown
CVE-2009-1235
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
0
Attacker Value
Unknown
CVE-2009-1236
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.
0
Attacker Value
Unknown
CVE-2009-1238
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.
0
Attacker Value
Unknown
CVE-2009-1237
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.
0
Attacker Value
Unknown
CVE-2007-2404
Disclosure Date: August 03, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2007-1863
Disclosure Date: June 27, 2007 (last updated February 16, 2024)
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
0
Attacker Value
Unknown
CVE-2007-0753
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
0
Attacker Value
Unknown
CVE-2007-0751
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.
0
Attacker Value
Unknown
CVE-2007-0729
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
0
Attacker Value
Unknown
CVE-2006-4866
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
0