VendorsApplemac_os_x10.3.9
Vulnerabilities

Apple Mac OS X 10.3.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

198CVEs
CVE-2005-2518
Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
Published 2005-08-19 · Modified
7.5EPSS 0.049
CVE-2005-2516
Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.
Published 2005-08-19 · Modified
7.5EPSS 0.048
CVE-2005-2743
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
Published 2005-10-25 · Modified
7.5EPSS 0.047
CVE-2006-3505
WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated.
Published 2006-08-03 · Modified
7.5EPSS 0.041
CVE-2006-0384
automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".
Published 2006-03-02 · Modified
7.5EPSS 0.040
CVE-2011-0230
Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Published 2011-10-14 · Modified
7.5EPSS 0.038
CVE-2005-3705
Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers to execute arbitrary code via unknown attack vectors.
Published 2005-12-01 · Modified
7.5EPSS 0.036
CVE-2005-2757
Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving "validation of URLs."
Published 2005-12-01 · Modified
7.5EPSS 0.035
CVE-2012-0662
Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.
Published 2012-05-11 · Modified
7.5EPSS 0.032
CVE-2006-1442
The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.
Published 2006-05-12 · Modified
7.5EPSS 0.030
CVE-2012-0650
Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Published 2012-09-20 · Modified
7.5EPSS 0.030
CVE-2005-2514
Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.
Published 2005-08-19 · Modified
7.5EPSS 0.026
CVE-2005-2505
Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.
Published 2005-08-19 · Modified
7.5EPSS 0.023
CVE-2005-1332
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
Published 2005-05-04 · Modified
7.5EPSS 0.019
CVE-2006-4410
The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows remote attackers to access systems by using revoked certificates.
Published 2006-11-30 · Modified
7.5EPSS 0.016
CVE-2005-1339
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
Published 2005-05-04 · Modified
7.5EPSS 0.013
CVE-2005-1340
The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
Published 2005-05-04 · Modified
7.5EPSS 0.013
CVE-2005-1337
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
Published 2005-05-04 · Modified
7.5EPSS 0.013
CVE-2006-3507
Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.
Published 2006-09-21 · Modified
7.21 PoCEPSS 0.015
CVE-2005-1343
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
Published 2005-05-04 · Modified
7.2EPSS 0.010
CVE-2009-1235
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
Published 2009-04-02 · Modified
7.21 PoCEPSS 0.010
CVE-2007-0753
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
Published 2007-05-24 · Modified
7.22 PoCEPSS 0.009
CVE-2007-0729
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
Published 2007-04-24 · Modified
7.2EPSS 0.009
CVE-2007-0747
load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.
Published 2007-04-24 · Modified
7.2EPSS 0.009
CVE-2005-1335
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
Published 2005-05-04 · Modified
7.2EPSS 0.008
CVE-2009-1238
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.
Published 2009-04-02 · Modified
7.21 PoCEPSS 0.006
CVE-2007-0725
Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."
Published 2007-04-24 · Modified
7.2EPSS 0.005
CVE-2005-0974
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
Published 2005-05-12 · Modified
7.2EPSS 0.004
CVE-2006-1451
MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.
Published 2006-05-12 · Modified
7.2EPSS 0.004
CVE-2007-0744
SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.
Published 2007-04-24 · Modified
7.2EPSS 0.004
CVE-2005-2519
slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges.
Published 2005-08-19 · Modified
7.2EPSS 0.004
CVE-2006-4411
The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly clean the environment when executing commands, which allows local users to gain privileges via unspecified vectors.
Published 2006-11-30 · Modified
7.2EPSS 0.004
CVE-2005-2741
Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators.
Published 2005-10-25 · Modified
7.2EPSS 0.003
CVE-2007-0646
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
Published 2007-02-01 · Modified
7.11 PoCEPSS 0.102
CVE-2007-2389
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets.
Published 2007-05-29 · Modified
7.1EPSS 0.028
CVE-2007-0647
Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.
Published 2007-02-01 · Modified
7.11 PoCEPSS 0.026
CVE-2007-4678
AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted.
Published 2007-11-15 · Modified
7.1EPSS 0.021
CVE-2007-0724
The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
Published 2007-03-13 · Modified
6.9EPSS 0.008
CVE-2007-4681
Buffer overflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted directory hierarchy.
Published 2007-11-15 · Modified
6.9EPSS 0.004
CVE-2012-0649
Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors involving a temporary file.
Published 2012-05-11 · Modified
6.9EPSS 0.003
← Prev2 / 5Next →