Apple

macOS X

3207 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.86%
  • Veröffentlicht 14.10.2011 10:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access.

  • EPSS 3.75%
  • Veröffentlicht 19.09.2011 12:02:55
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

  • EPSS 0.38%
  • Veröffentlicht 12.09.2011 12:40:44
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Ext...

  • EPSS 2.28%
  • Veröffentlicht 29.08.2011 15:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.

  • EPSS 1.51%
  • Veröffentlicht 07.07.2011 21:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSS...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 30.06.2011 15:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desktop hang) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstr...

  • EPSS 1.32%
  • Veröffentlicht 30.06.2011 15:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.

  • EPSS 0.05%
  • Veröffentlicht 24.06.2011 20:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.

  • EPSS 11.35%
  • Veröffentlicht 24.06.2011 20:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font.

  • EPSS 0.17%
  • Veröffentlicht 24.06.2011 20:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked cer...