CVE-2007-5862
- EPSS 0.21%
- Published 18.12.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a crafted Java applet.
CVE-2007-6359
- EPSS 0.2%
- Published 15.12.2007 01:46:00
- Last modified 09.04.2025 00:30:58
The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the ...
CVE-2007-6276
- EPSS 14%
- Published 07.12.2007 11:46:00
- Last modified 09.04.2025 00:30:58
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP ...
CVE-2007-6261
- EPSS 0.15%
- Published 06.12.2007 02:46:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the load_threadstack function in the Mach-O loader (mach_loader.c) in the xnu kernel in Apple Mac OS X 10.4 through 10.5.1 allows local users to cause a denial of service (infinite loop) via a crafted Mach-O binary.
CVE-2007-6165
- EPSS 38.55%
- Published 29.11.2007 01:46:00
- Last modified 09.04.2025 00:30:58
Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate ...
CVE-2007-4702
- EPSS 0.67%
- Published 15.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass inten...
- EPSS 0.66%
- Published 15.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root p...
- EPSS 0.81%
- Published 15.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
The Application Firewall in Apple Mac OS X 10.5 does not apply changed settings to processes that are started by launchd until the processes are restarted, which might allow attackers to bypass intended access restrictions.
CVE-2007-4700
- EPSS 0.65%
- Published 15.11.2007 02:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.
CVE-2007-4701
- EPSS 0.07%
- Published 15.11.2007 02:46:00
- Last modified 09.04.2025 00:30:58
WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.