CVE-2010-1820
- EPSS 0.32%
- Veröffentlicht 21.09.2010 20:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.
- EPSS 0.3%
- Veröffentlicht 25.08.2010 20:00:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.
CVE-2010-1801
- EPSS 1.49%
- Veröffentlicht 25.08.2010 20:00:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.
CVE-2010-1802
- EPSS 0.12%
- Veröffentlicht 25.08.2010 20:00:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name,...
CVE-2010-1808
- EPSS 1.39%
- Veröffentlicht 25.08.2010 20:00:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
CVE-2010-0211
- EPSS 42.37%
- Veröffentlicht 28.07.2010 12:48:51
- Zuletzt bearbeitet 11.04.2025 00:51:21
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code ...
CVE-2010-1205
- EPSS 17.03%
- Veröffentlicht 30.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
CVE-2010-1637
- EPSS 0.13%
- Veröffentlicht 22.06.2010 17:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
- EPSS 0.4%
- Veröffentlicht 17.06.2010 16:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for ...
CVE-2010-0541
- EPSS 1.42%
- Veröffentlicht 17.06.2010 16:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.