CVE-2006-4406
- EPSS 21.03%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is enabled, allows remote attackers to execute arbitrary code via unspecified vectors.
- EPSS 1.02%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Security Framework in Apple Mac OS X 10.3.x up to 10.3.9 does not properly prioritize encryption ciphers when negotiating the strongest shared cipher, which causes Secure Transport to user a weaker cipher that makes it easier for remote attackers...
- EPSS 0.34%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Security Framework in Apple Mac OS X 10.4 through 10.4.8 allows remote attackers to cause a denial of service (resource consumption) via certain public key values in an X.509 certificate that requires extra resources during signature verification...
- EPSS 0.88%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Online Certificate Status Protocol (OCSP) service in the Security Framework in Apple Mac OS X 10.4 through 10.4.8 retrieve certificate revocation lists (CRL) when an HTTP proxy is in use, which could cause the system to accept certificates that h...
CVE-2006-4410
- EPSS 0.39%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows remote attackers to access systems by using revoked certificates.
CVE-2006-4411
- EPSS 0.05%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly clean the environment when executing commands, which allows local users to gain privileges via unspecified vectors.
CVE-2006-4412
- EPSS 10.7%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebKit in Apple Mac OS X 10.3.x through 10.3.9 and 10.4 through 10.4.8 allows remote attackers to execute arbitrary code via a crafted HTML file, which accesses previously deallocated objects.
CVE-2006-6173
- EPSS 0.34%
- Veröffentlicht 30.11.2006 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number ...
CVE-2006-6126
- EPSS 0.09%
- Veröffentlicht 27.11.2006 00:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.
CVE-2006-6127
- EPSS 0.52%
- Veröffentlicht 27.11.2006 00:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.