| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2010-1846 |
Heap-based buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RAW image. Published: November 16, 2010; 5:00:15 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1845 |
ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image. Published: November 16, 2010; 5:00:15 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1844 |
Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consumption and system crash) via a crafted image. Published: November 16, 2010; 5:00:15 PM -0500 |
V3.x:(not available) V2.0: 7.1 HIGH |
| CVE-2010-1842 |
Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a bidirectional text string with ellipsis truncation. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2010-1841 |
Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2010-1840 |
Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2010-1838 |
Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 4.4 MEDIUM |
| CVE-2010-1837 |
CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a PDF document. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1836 |
Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1834 |
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 5.8 MEDIUM |
| CVE-2010-1833 |
Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1832 |
Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a crafted embedded font in a document. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1831 |
Buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a long name of an embedded font in a document. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1830 |
AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depending on whether a share exists, which allows remote attackers to enumerate valid share names via unspecified vectors. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2010-1829 |
Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to execute arbitrary code by creating files that are outside the bounds of a share. Published: November 15, 2010; 6:00:04 PM -0500 |
V3.x:(not available) V2.0: 6.0 MEDIUM |
| CVE-2010-1828 |
AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets. Published: November 15, 2010; 6:00:03 PM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2010-1803 |
Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume. Published: November 15, 2010; 6:00:03 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2010-1378 |
OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority. Published: November 15, 2010; 6:00:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2010-4091 |
The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information. Published: November 07, 2010; 5:00:03 PM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2010-3638 |
Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Mac OS X, when Safari is used, allows attackers to obtain sensitive information via unknown vectors. Published: November 07, 2010; 5:00:01 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |