Apple

macOS X

3207 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Published 18.12.2007 20:46:00
  • Last modified 09.04.2025 00:30:58

Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a crafted Java applet.

Exploit
  • EPSS 0.2%
  • Published 15.12.2007 01:46:00
  • Last modified 09.04.2025 00:30:58

The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the ...

Exploit
  • EPSS 14%
  • Published 07.12.2007 11:46:00
  • Last modified 09.04.2025 00:30:58

The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP ...

Exploit
  • EPSS 0.15%
  • Published 06.12.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

Integer overflow in the load_threadstack function in the Mach-O loader (mach_loader.c) in the xnu kernel in Apple Mac OS X 10.4 through 10.5.1 allows local users to cause a denial of service (infinite loop) via a crafted Mach-O binary.

Exploit
  • EPSS 38.55%
  • Published 29.11.2007 01:46:00
  • Last modified 09.04.2025 00:30:58

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate ...

  • EPSS 0.67%
  • Published 15.11.2007 20:46:00
  • Last modified 09.04.2025 00:30:58

The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass inten...

  • EPSS 0.66%
  • Published 15.11.2007 20:46:00
  • Last modified 09.04.2025 00:30:58

The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root p...

  • EPSS 0.81%
  • Published 15.11.2007 20:46:00
  • Last modified 09.04.2025 00:30:58

The Application Firewall in Apple Mac OS X 10.5 does not apply changed settings to processes that are started by launchd until the processes are restarted, which might allow attackers to bypass intended access restrictions.

  • EPSS 0.65%
  • Published 15.11.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.

  • EPSS 0.07%
  • Published 15.11.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.