CVE-2009-2812
- EPSS 1.74%
- Published 14.09.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execu...
- EPSS 0.44%
- Published 14.09.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle error...
CVE-2009-2814
- EPSS 0.5%
- Published 14.09.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple Mac OS X 10.5.8 allows remote attackers to inject arbitrary web script or HTML via a search request containing data that does not use UTF-8 encoding.
CVE-2009-2800
- EPSS 0.96%
- Published 11.09.2009 18:30:03
- Last modified 09.04.2025 00:30:58
Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted alias file.
CVE-2009-2205
- EPSS 0.84%
- Published 09.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
- EPSS 19.51%
- Published 12.08.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
CVE-2009-2416
- EPSS 0.19%
- Published 11.08.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
CVE-2009-1726
- EPSS 11.3%
- Published 06.08.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.
CVE-2009-1727
- EPSS 0.56%
- Published 06.08.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the...
CVE-2009-1728
- EPSS 9.72%
- Published 06.08.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a craft...