Show filters
131 Total Results
Displaying 81-90 of 131
Sort by:
Attacker Value
Unknown

CVE-2008-4212

Disclosure Date: October 10, 2008 (last updated October 04, 2023)
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which might allow remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2008-3647

Disclosure Date: October 10, 2008 (last updated October 04, 2023)
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.
0
Attacker Value
Unknown

CVE-2008-3642

Disclosure Date: October 10, 2008 (last updated October 04, 2023)
Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
0
Attacker Value
Unknown

CVE-2008-3637

Disclosure Date: September 26, 2008 (last updated February 16, 2024)
The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an "error checking issue."
Attacker Value
Unknown

CVE-2008-2330

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
0
Attacker Value
Unknown

CVE-2008-3616

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
0
Attacker Value
Unknown

CVE-2008-2305

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."
0
Attacker Value
Unknown

CVE-2008-3611

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
0
Attacker Value
Unknown

CVE-2008-2332

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
0
Attacker Value
Unknown

CVE-2008-3608

Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
0