Show filters
77 Total Results
Displaying 51-60 of 77
Sort by:
Attacker Value
Unknown

CVE-2013-1026

Disclosure Date: September 16, 2013 (last updated October 05, 2023)
Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.
0
Attacker Value
Unknown

CVE-2013-1028

Disclosure Date: September 16, 2013 (last updated October 05, 2023)
The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-3953

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8.x does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted call.
0
Attacker Value
Unknown

CVE-2013-3950

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the openSharedCacheFile function in dyld.cpp in dyld in Apple iOS 5.1.x and 6.x through 6.1.3 makes it easier for attackers to conduct untethering attacks via a long string in the DYLD_SHARED_CACHE_DIR environment variable.
0
Attacker Value
Unknown

CVE-2013-3951

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.
0
Attacker Value
Unknown

CVE-2013-3954

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size value in conjunction with a crafted buffer.
0
Attacker Value
Unknown

CVE-2013-3948

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download-manifest itms-services:// URL that leverages an open redirect vulnerability within a trusted domain.
0
Attacker Value
Unknown

CVE-2013-3955

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem.
0
Attacker Value
Unknown

CVE-2013-1019

Disclosure Date: May 24, 2013 (last updated October 05, 2023)
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
0
Attacker Value
Unknown

CVE-2013-2842

Disclosure Date: May 22, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.
0