Apple

macOS X

3207 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.83%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.

  • EPSS 1.39%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

  • EPSS 0.05%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibl...

  • EPSS 2.19%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a "long pathname with an unexpected structure" that triggers the overflow in NSFileManager.

  • EPSS 4.86%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.

  • EPSS 0.96%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."

  • EPSS 1.94%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.

  • EPSS 0.4%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.

  • EPSS 0.07%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to execute arbitrary code via format string specifiers in the local hostname.

  • EPSS 0.07%
  • Published 18.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving...