Page 225 of 2413 results (0.018 seconds)

CVSS: 5.5EPSS: 0%CPEs: 4EXPL: 0

25 Oct 2005 — The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

25 Oct 2005 — Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

25 Oct 2005 — Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators. Authorization Services en securityd para Apple Mac OS X 10.3.9 permite a usuarios locales obtener privilegios garantizándose a sí mismos determinados derechos que deben de ser restringidos a administradores. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2005 — Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

19 Aug 2005 — Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

19 Aug 2005 — Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 4.6EPSS: 0%CPEs: 4EXPL: 0

19 Aug 2005 — AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

19 Aug 2005 — Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

19 Aug 2005 — Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2005 — Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •