Show filters
82 Total Results
Displaying 71-80 of 82
Sort by:
Attacker Value
Unknown
CVE-2013-0975
Disclosure Date: June 05, 2013 (last updated October 05, 2023)
Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
0
Attacker Value
Unknown
CVE-2013-3954
Disclosure Date: June 05, 2013 (last updated October 05, 2023)
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size value in conjunction with a crafted buffer.
0
Attacker Value
Unknown
CVE-2013-3952
Disclosure Date: June 05, 2013 (last updated October 05, 2023)
The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.
0
Attacker Value
Unknown
CVE-2013-1024
Disclosure Date: June 05, 2013 (last updated October 05, 2023)
CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
0
Attacker Value
Unknown
CVE-2013-0970
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirmation prompt via a crafted FaceTime: URL.
0
Attacker Value
Unknown
CVE-2013-0976
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image.
0
Attacker Value
Unknown
CVE-2013-0969
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary System Preferences changes via unspecified use of the keyboard.
0
Attacker Value
Unknown
CVE-2013-0967
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.
0
Attacker Value
Unknown
CVE-2013-0966
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
0
Attacker Value
Unknown
CVE-2013-0971
Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document.
0