Show filters
103 Total Results
Displaying 71-80 of 103
Sort by:
Attacker Value
Unknown

CVE-2009-0151

Disclosure Date: August 06, 2009 (last updated October 04, 2023)
The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-1717

Disclosure Date: June 05, 2009 (last updated October 04, 2023)
Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2009-0144

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.
0
Attacker Value
Unknown

CVE-2009-0154

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.
0
Attacker Value
Unknown

CVE-2009-0161

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.
0
Attacker Value
Unknown

CVE-2009-0145

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption.
0
Attacker Value
Unknown

CVE-2009-0150

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image.
0
Attacker Value
Unknown

CVE-2009-0943

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.
0
Attacker Value
Unknown

CVE-2009-0153

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2009-0160

Disclosure Date: May 13, 2009 (last updated October 04, 2023)
QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.
0