Page 209 of 2244 results (0.009 seconds)

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

25 Oct 2005 — Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators. Authorization Services en securityd para Apple Mac OS X 10.3.9 permite a usuarios locales obtener privilegios garantizándose a sí mismos determinados derechos que deben de ser restringidos a administradores. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.5EPSS: 0%CPEs: 4EXPL: 0

25 Oct 2005 — The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

25 Oct 2005 — Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 8.8EPSS: 3%CPEs: 26EXPL: 0

25 Oct 2005 — Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 9.1EPSS: 0%CPEs: 61EXPL: 0

19 Aug 2005 — Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2005 — slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2005 — Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

19 Aug 2005 — Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

19 Aug 2005 — Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 4.6EPSS: 0%CPEs: 4EXPL: 0

19 Aug 2005 — AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •