Show filters
151 Total Results
Displaying 71-80 of 151
Sort by:
Attacker Value
Unknown

CVE-2005-0712

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
0
Attacker Value
Unknown

CVE-2005-0342

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.
0
Attacker Value
Unknown

CVE-2005-0970

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow attackers to conduct unauthorized activities with escalated privileges via vulnerable scripts.
0
Attacker Value
Unknown

CVE-2004-0922

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
0
Attacker Value
Unknown

CVE-2004-0924

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
0
Attacker Value
Unknown

CVE-2004-0921

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
0
Attacker Value
Unknown

CVE-2004-0927

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
0
Attacker Value
Unknown

CVE-2004-0926

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
0
Attacker Value
Unknown

CVE-2004-0886

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
0
Attacker Value
Unknown

CVE-2004-0923

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.
0