Show filters
151 Total Results
Displaying 91-100 of 151
Sort by:
Attacker Value
Unknown
CVE-2008-2330
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
0
Attacker Value
Unknown
CVE-2008-3616
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
0
Attacker Value
Unknown
CVE-2008-3611
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
0
Attacker Value
Unknown
CVE-2008-2305
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."
0
Attacker Value
Unknown
CVE-2008-2332
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
0
Attacker Value
Unknown
CVE-2008-3608
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
0
Attacker Value
Unknown
CVE-2008-2312
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable file, which allows local users to obtain sensitive information by reading this file.
0
Attacker Value
Unknown
CVE-2008-3621
Disclosure Date: September 16, 2008 (last updated October 04, 2023)
VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving H.264 encoded media.
0
Attacker Value
Unknown
CVE-2008-2324
Disclosure Date: August 04, 2008 (last updated October 04, 2023)
The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.
0
Attacker Value
Unknown
CVE-2008-2313
Disclosure Date: July 01, 2008 (last updated October 04, 2023)
Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
0