Skip to main content

Vendor archive

apple CVEs

Beta · best-effort

15,000 CVEs tagged to vendor apple2,415 Critical, 6,162 High, 5,690 Medium, 733 Low, 0 Unrated.

CVE-2007-0463

Published Jan 29, 2007

Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0462

Published Jan 26, 2007

The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0478

Published Jan 25, 2007

WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0023

Published Jan 24, 2007

The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges vi…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0430

Published Jan 23, 2007

The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount val…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0021

Published Jan 23, 2007

Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0022

Published Jan 23, 2007

Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0345

Published Jan 18, 2007

The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool progra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0318

Published Jan 18, 2007

The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0299

Published Jan 17, 2007

Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0267

Published Jan 17, 2007

The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mou…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0236

Published Jan 16, 2007

Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0197

Published Jan 11, 2007

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0117

Published Jan 9, 2007

DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0102

Published Jan 9, 2007

The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop),…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0059

Published Jan 5, 2007

Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0051

Published Jan 4, 2007

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast w…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0015

Published Jan 1, 2007

Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6900

Published Dec 31, 2006

Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6906

Published Dec 31, 2006

Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5681

Published Dec 20, 2006

QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6652

Published Dec 20, 2006

Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 14,526-14,550 of 15,000 CVEsPage 582 of 600