Apple

macOS X Server

655 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.01%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read.

  • EPSS 1.23%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.

  • EPSS 1.91%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.

  • EPSS 1.38%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.

  • EPSS 0.18%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked cer...

  • EPSS 2.31%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invoca...

  • EPSS 2.31%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript fi...

  • EPSS 1.55%
  • Published 13.05.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application...

  • EPSS 15.24%
  • Published 17.04.2009 00:30:00
  • Last modified 09.04.2025 00:30:58

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

Exploit
  • EPSS 0.2%
  • Published 02.04.2009 17:30:00
  • Last modified 09.04.2025 00:30:58

XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk imag...