- EPSS 0.38%
- Published 02.02.2012 18:55:01
- Last modified 11.04.2025 00:51:21
Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a dif...
CVE-2011-3463
- EPSS 0.11%
- Published 02.02.2012 18:55:01
- Last modified 11.04.2025 00:51:21
WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server or (2) a bound directory.
CVE-2011-3919
- EPSS 2.5%
- Published 07.01.2012 11:55:13
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2008-7303
- EPSS 4.27%
- Published 15.11.2011 18:55:01
- Last modified 11.04.2025 00:51:21
The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to tri...
CVE-2011-1516
- EPSS 2.5%
- Published 15.11.2011 18:55:01
- Last modified 11.04.2025 00:51:21
The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, a...
CVE-2011-3435
- EPSS 0.12%
- Published 14.10.2011 10:55:11
- Last modified 11.04.2025 00:51:21
Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.
CVE-2011-3436
- EPSS 0.1%
- Published 14.10.2011 10:55:11
- Last modified 11.04.2025 00:51:21
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended works...
CVE-2011-3437
- EPSS 0.96%
- Published 14.10.2011 10:55:11
- Last modified 11.04.2025 00:51:21
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
CVE-2011-3223
- EPSS 2.4%
- Published 14.10.2011 10:55:09
- Last modified 11.04.2025 00:51:21
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.
CVE-2011-3224
- EPSS 0.53%
- Published 14.10.2011 10:55:09
- Last modified 11.04.2025 00:51:21
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.