CVE-2009-0154
- EPSS 18.4%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.
CVE-2009-0155
- EPSS 5.63%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via...
CVE-2009-0156
- EPSS 1.01%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read.
CVE-2009-0157
- EPSS 1.23%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.
CVE-2009-0158
- EPSS 1.91%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.
CVE-2009-0160
- EPSS 1.38%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.
CVE-2009-0161
- EPSS 0.18%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked cer...
CVE-2009-0942
- EPSS 2.31%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invoca...
CVE-2009-0943
- EPSS 2.31%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript fi...
CVE-2009-0944
- EPSS 1.55%
- Veröffentlicht 13.05.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application...