Page 274 of 2945 results (0.014 seconds)

CVSS: 7.8EPSS: 0%CPEs: 68EXPL: 1

14 Mar 2006 — Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow. • http://www.felinemenace.org/~nemo •

CVSS: 8.8EPSS: 7%CPEs: 32EXPL: 0

06 Mar 2006 — Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504. • http://docs.info.apple.com/article.html?artnum=303382 •

CVSS: 7.5EPSS: 0%CPEs: 12EXPL: 0

03 Mar 2006 — Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper. • http://docs.info.apple.com/article.html?artnum=303382 •

CVSS: 5.5EPSS: 0%CPEs: 32EXPL: 0

03 Mar 2006 — FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled. • http://docs.info.apple.com/article.html?artnum=303382 •

CVSS: 6.1EPSS: 1%CPEs: 12EXPL: 0

03 Mar 2006 — Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds. • http://docs.info.apple.com/article.html?artnum=303382 •

CVSS: 8.2EPSS: 1%CPEs: 32EXPL: 0

03 Mar 2006 — Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources. • http://docs.info.apple.com/article.html?artnum=303382 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.5EPSS: 2%CPEs: 32EXPL: 0

02 Mar 2006 — IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions". IPSec, cuando se usa con redes VPN en Max OS X 10.4 a 10.4.5 permite a atacantes remotos causar una denegación de servicio (caída de aplicación) mediante vectores no especificados implicando "manejo incorrecto de condiciones de error". • http://docs.info.apple.com/article.html?artnum=303382 •

CVSS: 9.8EPSS: 2%CPEs: 32EXPL: 0

02 Mar 2006 — automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names". • http://docs.info.apple.com/article.html?artnum=303382 •

CVSS: 8.8EPSS: 96%CPEs: 2EXPL: 4

22 Feb 2006 — The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension. • https://www.exploit-db.com/exploits/16866 • CWE-16: Configuration •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

14 Feb 2006 — Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call. • http://lists.apple.com/archives/security-announce/2006/Feb/msg00000.html •