Show filters
119 Total Results
Displaying 61-70 of 119
Sort by:
Attacker Value
Unknown

CVE-2007-4685

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, stderr, or stdout file descriptors are "in an unexpected state."
0
Attacker Value
Unknown

CVE-2007-4697

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption.
0
Attacker Value
Unknown

CVE-2007-4269

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2007-4694

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via file:// URLs.
0
Attacker Value
Unknown

CVE-2007-4687

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.
0
Attacker Value
Unknown

CVE-2007-4693

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between secure text fields."
0
Attacker Value
Unknown

CVE-2007-4690

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Double free vulnerability in the NFS component in Apple Mac OS X 10.4 through 10.4.10 allows remote authenticated users to execute arbitrary code via a crafted AUTH_UNIX RPC packet.
0
Attacker Value
Unknown

CVE-2007-2404

Disclosure Date: August 03, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2007-3744

Disclosure Date: August 03, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
0
Attacker Value
Unknown

CVE-2007-1863

Disclosure Date: June 27, 2007 (last updated February 16, 2024)
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
0