Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Filtered by product Mac Os X
Total 5567 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1087 1 Apple 4 Darwin Streaming Server, Mac Os X, Mac Os X Server and 1 more 2025-04-03 2.1 LOW N/A
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.
CVE-2003-1005 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.0 MEDIUM N/A
The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
CVE-2006-1442 1 Apple 1 Mac Os X 2025-04-03 7.5 HIGH N/A
The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.
CVE-2004-0923 2 Apple, Easy Software Products 3 Mac Os X, Mac Os X Server, Cups 2025-04-03 2.1 LOW N/A
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.
CVE-2006-3505 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 7.5 HIGH N/A
WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated.
CVE-2006-3496 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.0 MEDIUM N/A
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.
CVE-2002-1369 2 Apple, Easy Software Products 2 Mac Os X, Cups 2025-04-03 10.0 HIGH N/A
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
CVE-2006-1443 1 Apple 1 Mac Os X 2025-04-03 6.5 MEDIUM N/A
Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other similar API functions.
CVE-2006-0389 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.
CVE-2005-0712 1 Apple 1 Mac Os X 2025-04-03 4.6 MEDIUM N/A
Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
CVE-2002-0676 1 Apple 1 Mac Os X 2025-04-03 7.5 HIGH N/A
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.
CVE-2006-0400 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 7.5 HIGH N/A
CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."
CVE-2004-0489 1 Apple 1 Mac Os X 2025-04-03 7.6 HIGH N/A
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.
CVE-2005-1339 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 7.5 HIGH N/A
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
CVE-2005-2752 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 2.1 LOW N/A
An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability than CVE-2005-1126 and CVE-2005-1406.
CVE-2003-0878 1 Apple 1 Mac Os X 2025-04-03 2.1 LOW N/A
slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.
CVE-2004-0925 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.0 MEDIUM N/A
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
CVE-2005-2514 1 Apple 1 Mac Os X 2025-04-03 7.5 HIGH N/A
Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.
CVE-2005-2748 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 2.1 LOW N/A
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application.
CVE-2006-0388 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 2.6 LOW N/A
Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.