CVE-2013-1028
- EPSS 0.38%
- Published 16.09.2013 13:02:32
- Last modified 11.04.2025 00:51:21
The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a ...
CVE-2013-1029
- EPSS 0.5%
- Published 16.09.2013 13:02:32
- Last modified 11.04.2025 00:51:21
The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (panic) via crafted IGMP packets that leverage incorrect, extraneous code in the IGMP parser.
CVE-2013-1030
- EPSS 0.13%
- Published 16.09.2013 13:02:32
- Last modified 11.04.2025 00:51:21
mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the command line, which allows local users to obtain sensitive information by listing the process.
CVE-2013-1031
- EPSS 0.04%
- Published 16.09.2013 13:02:32
- Last modified 11.04.2025 00:51:21
Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences of a power assertion, which allows physically proximate attackers to bypass intended access restrictions by visiting an unattended workstation on whic...
CVE-2013-1032
- EPSS 2.02%
- Published 16.09.2013 13:02:32
- Last modified 11.04.2025 00:51:21
QuickTime in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted idsc atom in a QuickTime movie file.
CVE-2013-1033
- EPSS 0.08%
- Published 16.09.2013 13:02:32
- Last modified 11.04.2025 00:51:21
Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging screen-sharing access.
CVE-2013-1025
- EPSS 1.13%
- Published 16.09.2013 13:02:29
- Last modified 11.04.2025 00:51:21
Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document.
CVE-2013-3954
- EPSS 0.12%
- Published 05.06.2013 14:39:57
- Last modified 11.04.2025 00:51:21
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with...
CVE-2013-0975
- EPSS 0.89%
- Published 05.06.2013 14:39:55
- Last modified 11.04.2025 00:51:21
Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
CVE-2013-0982
- EPSS 0.05%
- Published 05.06.2013 14:39:55
- Last modified 11.04.2025 00:51:21
The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an una...