CVE-2002-0676
- EPSS 6.42%
- Published 11.07.2002 04:00:00
- Last modified 03.04.2025 01:03:51
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, ...
CVE-2001-1565
- EPSS 0.18%
- Published 31.12.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.
CVE-2001-0720
- EPSS 1.01%
- Published 06.12.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.
CVE-2001-0806
- EPSS 0.08%
- Published 06.12.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.
CVE-2001-1447
- EPSS 0.07%
- Published 17.10.2001 04:00:00
- Last modified 03.04.2025 01:03:51
NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges.
CVE-2001-1446
- EPSS 0.53%
- Published 11.09.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.
CVE-1999-0524
- EPSS 0.7%
- Published 01.08.1997 04:00:00
- Last modified 03.04.2025 01:03:51
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.