Show filters
641 Total Results
Displaying 581-590 of 641
Sort by:
Attacker Value
Unknown
CVE-2011-3213
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.
0
Attacker Value
Unknown
CVE-2011-3222
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
0
Attacker Value
Unknown
CVE-2011-2192
Disclosure Date: July 07, 2011 (last updated October 04, 2023)
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
0
Attacker Value
Unknown
CVE-2011-1752
Disclosure Date: June 06, 2011 (last updated October 04, 2023)
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
0
Attacker Value
Unknown
CVE-2011-1783
Disclosure Date: June 06, 2011 (last updated October 04, 2023)
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
0
Attacker Value
Unknown
CVE-2010-4008
Disclosure Date: December 07, 2010 (last updated October 04, 2023)
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
0
Attacker Value
Unknown
CVE-2010-2941
Disclosure Date: November 05, 2010 (last updated February 03, 2024)
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
0
Attacker Value
Unknown
CVE-2009-2818
Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force attack (aka dictionary attack).
0
Attacker Value
Unknown
CVE-2009-2834
Disclosure Date: November 10, 2009 (last updated October 04, 2023)
IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) Bluetooth keyboard via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-2832
Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a "CWD command line tool."
0