- EPSS 19.69%
- Veröffentlicht 13.05.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in a...
- EPSS 19.69%
- Veröffentlicht 13.05.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbitrary code via multiple trackID values in a SETUP RTSP request.
- EPSS 0.76%
- Veröffentlicht 18.07.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different v...
- EPSS 0.79%
- Veröffentlicht 10.01.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
CVE-2004-1083
- EPSS 1.91%
- Veröffentlicht 03.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning wit...
CVE-2004-1089
- EPSS 0.09%
- Veröffentlicht 02.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.
CVE-2004-1088
- EPSS 1.55%
- Veröffentlicht 02.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
CVE-2004-1087
- EPSS 0.09%
- Veröffentlicht 02.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.
CVE-2004-1086
- EPSS 3.08%
- Veröffentlicht 02.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.
CVE-2004-1085
- EPSS 0.07%
- Veröffentlicht 02.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.