VendorsAppleiphotoall versions
Vulnerabilities

Apple iPhoto

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2008-0043
Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.
Published 2008-02-08 · Modified
9.3EPSS 0.039
CVE-2008-0830
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.
Published 2008-02-19 · Modified
7.51 PoCEPSS 0.022
CVE-2007-0051
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
Published 2007-01-04 · Modified
6.81 PoCEPSS 0.091
CVE-2008-0987
Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7.1.2, allows remote attackers to execute arbitrary code via a crafted Adobe Digital Negative (DNG) image.
Published 2008-03-18 · Modified
6.8EPSS 0.048
CVE-2007-0645
Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.
Published 2007-02-01 · Modified
6.81 PoCEPSS 0.019