Page 251 of 2650 results (0.014 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

08 Jun 2005 — MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials. • http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html •

CVSS: 6.5EPSS: 18%CPEs: 6EXPL: 0

19 May 2005 — bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb"). • ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc • CWE-400: Uncontrolled Resource Consumption •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

19 May 2005 — Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories. • http://lists.apple.com/archives/security-announce/2005/May/msg00004.html •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 2

17 May 2005 — The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory. • https://www.exploit-db.com/exploits/680 •

CVSS: 7.8EPSS: 0%CPEs: 29EXPL: 0

12 May 2005 — Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.8EPSS: 0%CPEs: 30EXPL: 0

12 May 2005 — Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 5.5EPSS: 0%CPEs: 30EXPL: 0

12 May 2005 — Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.8EPSS: 0%CPEs: 54EXPL: 0

12 May 2005 — Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.8EPSS: 0%CPEs: 30EXPL: 0

12 May 2005 — Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

04 May 2005 — Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner." • http://lists.apple.com/archives/security-announce/2005/May/msg00001.html •