CVE-2010-0518
- EPSS 2.06%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with Sorenson encoding.
CVE-2010-0519
- EPSS 5.78%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles f...
CVE-2010-0520
- EPSS 9.15%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI ...
- EPSS 0.27%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.
CVE-2010-0524
- EPSS 0.38%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a cr...
- EPSS 0.13%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive i...
CVE-2010-0526
- EPSS 5.05%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPE...
- EPSS 0.14%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.
CVE-2010-0535
- EPSS 0.17%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions ...
CVE-2010-0537
- EPSS 0.24%
- Published 30.03.2010 18:30:01
- Last modified 11.04.2025 00:51:21
DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a craft...