CVE-2009-0156
- EPSS 1.01%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read.
CVE-2009-0157
- EPSS 1.23%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.
CVE-2009-0158
- EPSS 1.91%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.
CVE-2009-0160
- EPSS 1.38%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.
CVE-2009-0161
- EPSS 0.18%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked cer...
CVE-2009-0942
- EPSS 2.31%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invoca...
CVE-2009-0943
- EPSS 2.31%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript fi...
CVE-2009-0944
- EPSS 1.55%
- Published 13.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application...
CVE-2009-0946
- EPSS 15.24%
- Published 17.04.2009 00:30:00
- Last modified 09.04.2025 00:30:58
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
CVE-2009-1235
- EPSS 0.2%
- Published 02.04.2009 17:30:00
- Last modified 09.04.2025 00:30:58
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk imag...