- EPSS 58.86%
- Veröffentlicht 12.09.2008 16:56:20
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
CVE-2008-2939
- EPSS 67.24%
- Veröffentlicht 06.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary we...
CVE-2008-2324
- EPSS 0.05%
- Veröffentlicht 04.08.2008 01:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.
CVE-2008-3438
- EPSS 0.43%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
CVE-2008-2934
- EPSS 5.58%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.
CVE-2008-2309
- EPSS 2.46%
- Veröffentlicht 01.07.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the...
CVE-2008-2310
- EPSS 0.86%
- Veröffentlicht 01.07.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
CVE-2008-2311
- EPSS 2.89%
- Veröffentlicht 01.07.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.
CVE-2008-2313
- EPSS 0.05%
- Veröffentlicht 01.07.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
CVE-2008-2314
- EPSS 0.08%
- Veröffentlicht 01.07.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.