Apple

macOS X

3207 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.42%
  • Published 11.07.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, ...

  • EPSS 0.18%
  • Published 31.12.2001 05:00:00
  • Last modified 03.04.2025 01:03:51

Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.

  • EPSS 1.01%
  • Published 06.12.2001 05:00:00
  • Last modified 03.04.2025 01:03:51

Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.

  • EPSS 0.08%
  • Published 06.12.2001 05:00:00
  • Last modified 03.04.2025 01:03:51

Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.

Exploit
  • EPSS 0.07%
  • Published 17.10.2001 04:00:00
  • Last modified 03.04.2025 01:03:51

NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges.

  • EPSS 0.53%
  • Published 11.09.2001 04:00:00
  • Last modified 03.04.2025 01:03:51

Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.

  • EPSS 0.7%
  • Published 01.08.1997 04:00:00
  • Last modified 03.04.2025 01:03:51

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.