CVE-2008-3647
- EPSS 5.56%
- Published 10.10.2008 10:30:05
- Last modified 09.04.2025 00:30:58
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.
- EPSS 13.96%
- Published 10.10.2008 10:30:05
- Last modified 09.04.2025 00:30:58
Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) an...
- EPSS 0.8%
- Published 10.10.2008 10:30:05
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which might allow remote attackers to bypass intended access restrictions.
CVE-2008-4214
- EPSS 0.07%
- Published 10.10.2008 10:30:05
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an "insecure file operation" on temporary files.
CVE-2008-4215
- EPSS 0.71%
- Published 10.10.2008 10:30:05
- Last modified 09.04.2025 00:30:58
Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that has multiple short names, which might allow attackers to bypass intended access restrictions.
CVE-2008-3642
- EPSS 24.95%
- Published 10.10.2008 10:30:04
- Last modified 09.04.2025 00:30:58
Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
CVE-2008-3643
- EPSS 1.03%
- Published 10.10.2008 10:30:04
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a denial of service (continuous termination and restart) via a crafted Desktop file that generates an error when producing its icon, related to an "error r...
CVE-2008-3645
- EPSS 0.07%
- Published 10.10.2008 10:30:04
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Networking component) in Mac OS X 10.4.11 and 10.5.5 allows local users to execute arbitrary code via unknown vectors.
CVE-2008-3638
- EPSS 1.86%
- Published 26.09.2008 16:21:44
- Last modified 09.04.2025 00:30:58
Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.
CVE-2008-3637
- EPSS 12.48%
- Published 26.09.2008 16:21:43
- Last modified 09.04.2025 00:30:58
The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an "error checki...