CVE-2007-5850
- EPSS 0.76%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in Desktop Services in Apple Mac OS X 10.4.11 allows user-assisted attackers to execute arbitrary code via a directory with a crafted .DS_Store file.
CVE-2007-5851
- EPSS 0.2%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
iChat in Apple Mac OS X 10.4.11 allows network-adjacent remote attackers to automatically initiate a video connection to another user via unknown vectors.
CVE-2007-5853
- EPSS 0.84%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in IO Storage Family in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (system shutdown) or execute arbitrary code via a disk image with crafted GUID partition maps, which triggers memory ...
CVE-2007-5854
- EPSS 0.31%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Launch Services in Apple Mac OS X 10.4.11 and 10.5.1 does not treat HTML files as unsafe content, which allows attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via a crafted HTML file.
CVE-2007-5855
- EPSS 0.42%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when MD5 Challenge-Response authentication is available, which makes it easier for remote attackers to snif...
CVE-2007-5856
- EPSS 0.29%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote attackers to obtain sensitive information.
CVE-2007-5857
- EPSS 0.5%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which might allow remote attackers to obtain sensitive information via HREFTrack.
CVE-2007-5860
- EPSS 0.06%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Spin Tracer in Apple Mac OS X 10.5.1 allows local users to execute arbitrary code via unspecified output files, involving an "insecure file operation."
CVE-2007-5861
- EPSS 0.75%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Spotlight in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted .XLS file that triggers memory corruption in the Microsoft ...
CVE-2007-5863
- EPSS 74.39%
- Published 19.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the client and the server, using a modified distribution definition file with the "allow-external-scripts" op...