CVE-2008-4236
- EPSS 0.6%
- Veröffentlicht 17.12.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file.
- EPSS 0.52%
- Veröffentlicht 17.12.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context-dependent attackers to have an unspecified impact by leveraging unintended settings, as demonstrated...
CVE-2008-5183
- EPSS 1.97%
- Veröffentlicht 21.11.2008 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggere...
CVE-2008-3646
- EPSS 0.76%
- Veröffentlicht 10.10.2008 10:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.
CVE-2008-3647
- EPSS 5.56%
- Veröffentlicht 10.10.2008 10:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.
- EPSS 13.96%
- Veröffentlicht 10.10.2008 10:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) an...
- EPSS 0.8%
- Veröffentlicht 10.10.2008 10:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which might allow remote attackers to bypass intended access restrictions.
CVE-2008-4214
- EPSS 0.07%
- Veröffentlicht 10.10.2008 10:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an "insecure file operation" on temporary files.
CVE-2008-3642
- EPSS 24.95%
- Veröffentlicht 10.10.2008 10:30:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
CVE-2008-3643
- EPSS 1.03%
- Veröffentlicht 10.10.2008 10:30:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a denial of service (continuous termination and restart) via a crafted Desktop file that generates an error when producing its icon, related to an "error r...