Page 277 of 2946 results (0.009 seconds)

CVSS: 8.8EPSS: 3%CPEs: 26EXPL: 0

25 Oct 2005 — Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

25 Oct 2005 — Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

25 Oct 2005 — SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from sleep or screen saver" setting. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 9.8EPSS: 2%CPEs: 3EXPL: 0

25 Oct 2005 — The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 5.5EPSS: 0%CPEs: 4EXPL: 0

25 Oct 2005 — The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 8.8EPSS: 6%CPEs: 2EXPL: 0

25 Oct 2005 — Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

25 Oct 2005 — Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

25 Oct 2005 — Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators. Authorization Services en securityd para Apple Mac OS X 10.3.9 permite a usuarios locales obtener privilegios garantizándose a sí mismos determinados derechos que deben de ser restringidos a administradores. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2005 — Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

19 Aug 2005 — Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates. • http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html •