CVE-2008-2308
- EPSS 0.09%
- Veröffentlicht 01.07.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafte...
CVE-2008-2830
- EPSS 0.13%
- Veröffentlicht 23.06.2008 20:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands...
CVE-2008-1027
- EPSS 0.52%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic.
CVE-2008-1028
- EPSS 6.12%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document wi...
- EPSS 1.93%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, ...
CVE-2008-1031
- EPSS 3.19%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable.
CVE-2008-1032
- EPSS 4.34%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which ...
CVE-2008-1034
- EPSS 20.15%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted help:topic URL that triggers a buffer overflow.
CVE-2008-1036
- EPSS 2.64%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow re...
- EPSS 0.75%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.