Page 277 of 2945 results (0.010 seconds)

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

25 Oct 2005 — Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

25 Oct 2005 — SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from sleep or screen saver" setting. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 9.8EPSS: 2%CPEs: 3EXPL: 0

25 Oct 2005 — The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 5.5EPSS: 0%CPEs: 4EXPL: 0

25 Oct 2005 — The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 8.8EPSS: 6%CPEs: 2EXPL: 0

25 Oct 2005 — Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

25 Oct 2005 — Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

25 Oct 2005 — Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators. Authorization Services en securityd para Apple Mac OS X 10.3.9 permite a usuarios locales obtener privilegios garantizándose a sí mismos determinados derechos que deben de ser restringidos a administradores. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2005 — Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

19 Aug 2005 — Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

19 Aug 2005 — Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •