CVE-2010-1834
- EPSS 0.29%
- Published 15.11.2010 23:00:04
- Last modified 11.04.2025 00:51:21
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.
CVE-2010-1836
- EPSS 1.49%
- Published 15.11.2010 23:00:04
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
CVE-2010-1837
- EPSS 1.93%
- Published 15.11.2010 23:00:04
- Last modified 11.04.2025 00:51:21
CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a PDF document.
CVE-2010-1838
- EPSS 0.09%
- Published 15.11.2010 23:00:04
- Last modified 11.04.2025 00:51:21
Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.
CVE-2010-1840
- EPSS 4.36%
- Published 15.11.2010 23:00:04
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspec...
CVE-2010-1841
- EPSS 2.19%
- Published 15.11.2010 23:00:04
- Last modified 11.04.2025 00:51:21
Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.
CVE-2010-1842
- EPSS 3.18%
- Published 15.11.2010 23:00:04
- Last modified 11.04.2025 00:51:21
Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a bidirectional text string with ellipsis truncation.
CVE-2010-1803
- EPSS 0.31%
- Published 15.11.2010 23:00:03
- Last modified 11.04.2025 00:51:21
Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.
- EPSS 0.98%
- Published 15.11.2010 23:00:03
- Last modified 11.04.2025 00:51:21
AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets.
CVE-2010-1378
- EPSS 0.23%
- Published 15.11.2010 23:00:01
- Last modified 11.04.2025 00:51:21
OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.