CVE-2013-0990
- EPSS 0.43%
- Veröffentlicht 05.06.2013 14:39:55
- Zuletzt bearbeitet 11.04.2025 00:51:21
SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors.
CVE-2013-1024
- EPSS 0.9%
- Veröffentlicht 05.06.2013 14:39:55
- Zuletzt bearbeitet 11.04.2025 00:51:21
CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie ...
CVE-2013-0971
- EPSS 1.47%
- Veröffentlicht 15.03.2013 20:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document.
CVE-2013-0973
- EPSS 0.35%
- Veröffentlicht 15.03.2013 20:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketing-text WebView, which allows man-in-the-middle attackers to execute plugin code by modifying the client-server data stream.
CVE-2013-0966
- EPSS 0.24%
- Veröffentlicht 15.03.2013 20:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted path...
CVE-2013-0967
- EPSS 0.33%
- Veröffentlicht 15.03.2013 20:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.
CVE-2012-3489
- EPSS 1.04%
- Veröffentlicht 03.10.2012 21:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or U...
CVE-2012-3722
- EPSS 2.12%
- Veröffentlicht 20.09.2012 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a...
CVE-2012-3723
- EPSS 0.08%
- Veröffentlicht 20.09.2012 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a ...
CVE-2012-0650
- EPSS 1.4%
- Veröffentlicht 20.09.2012 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.