Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown

CVE-2011-3444

Disclosure Date: February 02, 2012 (last updated October 04, 2023)
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
0
Attacker Value
Unknown

CVE-2011-3453

Disclosure Date: February 02, 2012 (last updated October 04, 2023)
Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via crafted DNS data.
0
Attacker Value
Unknown

CVE-2011-1516

Disclosure Date: November 15, 2011 (last updated October 04, 2023)
The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.
0
Attacker Value
Unknown

CVE-2011-3246

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.
0
Attacker Value
Unknown

CVE-2011-3225

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody account.
0
Attacker Value
Unknown

CVE-2011-3437

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
0
Attacker Value
Unknown

CVE-2011-0260

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window.
0
Attacker Value
Unknown

CVE-2011-3436

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.
0
Attacker Value
Unknown

CVE-2011-3226

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account.
0
Attacker Value
Unknown

CVE-2011-3435

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.
0