CVE-2005-1330
- EPSS 0.06%
- Veröffentlicht 04.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
CVE-2005-1331
- EPSS 1.13%
- Veröffentlicht 04.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executi...
CVE-2005-1332
- EPSS 1.3%
- Veröffentlicht 04.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
CVE-2005-1335
- EPSS 0.48%
- Veröffentlicht 04.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
CVE-2005-1337
- EPSS 0.55%
- Veröffentlicht 04.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
CVE-2005-1339
- EPSS 0.64%
- Veröffentlicht 04.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
CVE-2005-1341
- EPSS 0.85%
- Veröffentlicht 04.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
CVE-2005-1343
- EPSS 0.07%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
CVE-2005-1430
- EPSS 0.05%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
CVE-2005-0125
- EPSS 0.05%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f arg...