| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2013-5163 |
Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrary Directory Services records via unspecified vectors. Published: October 04, 2013; 6:44:07 AM -0400 |
V3.x:(not available) V2.0: 6.6 MEDIUM |
| CVE-2013-1130 |
Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a crafted library file, aka Bug ID CSCue33619. Published: September 20, 2013; 12:55:07 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-2391 |
The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets. Published: September 19, 2013; 6:27:53 AM -0400 |
V3.x:(not available) V2.0: 6.1 MEDIUM |
| CVE-2013-1729 |
The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element. Published: September 18, 2013; 6:08:24 AM -0400 |
V3.x:(not available) V2.0: 2.6 LOW |
| CVE-2013-1824 |
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. Published: September 16, 2013; 9:02:34 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2013-1033 |
Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging screen-sharing access. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 5.5 MEDIUM |
| CVE-2013-1032 |
QuickTime in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted idsc atom in a QuickTime movie file. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2013-1031 |
Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences of a power assertion, which allows physically proximate attackers to bypass intended access restrictions by visiting an unattended workstation on which a locking failure had prevented the startup of the screen saver. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 3.3 LOW |
| CVE-2013-1030 |
mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the command line, which allows local users to obtain sensitive information by listing the process. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-2013-1029 |
The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (panic) via crafted IGMP packets that leverage incorrect, extraneous code in the IGMP parser. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 4.9 MEDIUM |
| CVE-2013-1028 |
The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 5.8 MEDIUM |
| CVE-2013-1027 |
Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which might allow user-assisted remote attackers to execute arbitrary code via a crafted package. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2013-1026 |
Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document. Published: September 16, 2013; 9:02:32 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2013-1025 |
Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document. Published: September 16, 2013; 9:02:29 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2013-3358 |
Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3357. Published: September 12, 2013; 9:28:24 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-3357 |
Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358. Published: September 12, 2013; 9:28:24 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-3356 |
Buffer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3353. Published: September 12, 2013; 9:28:24 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-3355 |
Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3352 and CVE-2013-3354. Published: September 12, 2013; 9:28:24 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-3354 |
Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3352 and CVE-2013-3355. Published: September 12, 2013; 9:28:24 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-3353 |
Buffer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3356. Published: September 12, 2013; 9:28:24 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |