Page 199 of 2061 results (0.013 seconds)

CVSS: 9.1EPSS: 0%CPEs: 61EXPL: 0

19 Aug 2005 — Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 9.8EPSS: 43%CPEs: 5EXPL: 0

17 Jul 2005 — Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions. Vulnerabilidad de doble liberación de memoria en la función krb5_recvauth en MIT Kerberos 5 (krb5) 1.4.1 y anteriores permite que atacantes remotos ejecuten código arbitrario mediante ciertas condiciones de error. • ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc • CWE-415: Double Free •

CVSS: 6.5EPSS: 18%CPEs: 6EXPL: 0

19 May 2005 — bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb"). • ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc • CWE-400: Uncontrolled Resource Consumption •

CVSS: 7.8EPSS: 0%CPEs: 29EXPL: 0

12 May 2005 — Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.8EPSS: 0%CPEs: 30EXPL: 0

12 May 2005 — Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 5.5EPSS: 0%CPEs: 30EXPL: 0

12 May 2005 — Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.8EPSS: 0%CPEs: 54EXPL: 0

12 May 2005 — Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.8EPSS: 0%CPEs: 30EXPL: 0

12 May 2005 — Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.1EPSS: 0%CPEs: 56EXPL: 1

03 May 2005 — Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users. • http://www.security-focus.com/archive/1/397306 •

CVSS: 8.8EPSS: 0%CPEs: 30EXPL: 0

22 Apr 2005 — Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow attackers to conduct unauthorized activities with escalated privileges via vulnerable scripts. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html • CWE-264: Permissions, Privileges, and Access Controls •