CVE-2008-0055
- EPSS 0.05%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibl...
CVE-2008-0056
- EPSS 2.19%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a "long pathname with an unexpected structure" that triggers the overflow in NSFileManager.
CVE-2008-0058
- EPSS 4.86%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.
CVE-2008-0059
- EPSS 0.96%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
CVE-2008-0060
- EPSS 1.94%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.
CVE-2008-0988
- EPSS 0.4%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.
CVE-2008-0989
- EPSS 0.07%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to execute arbitrary code via format string specifiers in the local hostname.
CVE-2008-0990
- EPSS 0.07%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving...
CVE-2008-0992
- EPSS 1.26%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value.
CVE-2008-0994
- EPSS 0.35%
- Veröffentlicht 18.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.