Show filters
82 Total Results
Displaying 71-80 of 82
Sort by:
Attacker Value
Unknown

CVE-2013-0975

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
0
Attacker Value
Unknown

CVE-2013-3954

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size value in conjunction with a crafted buffer.
0
Attacker Value
Unknown

CVE-2013-3952

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.
0
Attacker Value
Unknown

CVE-2013-1024

Disclosure Date: June 05, 2013 (last updated October 05, 2023)
CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
0
Attacker Value
Unknown

CVE-2013-0970

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirmation prompt via a crafted FaceTime: URL.
0
Attacker Value
Unknown

CVE-2013-0976

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image.
0
Attacker Value
Unknown

CVE-2013-0969

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary System Preferences changes via unspecified use of the keyboard.
0
Attacker Value
Unknown

CVE-2013-0967

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.
0
Attacker Value
Unknown

CVE-2013-0966

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
0
Attacker Value
Unknown

CVE-2013-0971

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document.
0