Apple

macOS X

3207 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 15.24%
  • Veröffentlicht 17.04.2009 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

  • EPSS 23.59%
  • Veröffentlicht 09.04.2009 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 02.04.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk imag...

Exploit
  • EPSS 4.82%
  • Veröffentlicht 02.04.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwri...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 02.04.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 02.04.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS co...

  • EPSS 3.94%
  • Veröffentlicht 22.02.2009 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a cr...

  • EPSS 2.5%
  • Veröffentlicht 13.02.2009 00:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.

  • EPSS 0.79%
  • Veröffentlicht 13.02.2009 00:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.

  • EPSS 0.43%
  • Veröffentlicht 13.02.2009 00:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.