CVE-2009-2800
- EPSS 0.96%
- Veröffentlicht 11.09.2009 18:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted alias file.
CVE-2009-2205
- EPSS 0.84%
- Veröffentlicht 09.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
- EPSS 3.99%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2474
- EPSS 0.43%
- Veröffentlicht 21.08.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers vi...
- EPSS 19.51%
- Veröffentlicht 12.08.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
CVE-2009-2416
- EPSS 0.19%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
CVE-2009-1726
- EPSS 11.3%
- Veröffentlicht 06.08.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.
CVE-2009-1727
- EPSS 0.56%
- Veröffentlicht 06.08.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the...
CVE-2009-1728
- EPSS 9.72%
- Veröffentlicht 06.08.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a craft...
CVE-2009-2188
- EPSS 18.34%
- Veröffentlicht 06.08.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with crafted EXIF metadata.