Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Total 14474 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1442 1 Apple 1 Mac Os X 2026-04-16 7.5 HIGH N/A
The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.
CVE-2004-1021 1 Apple 1 Ical 2026-04-16 7.5 HIGH N/A
iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.
CVE-2005-2503 1 Apple 2 Mac Os X, Mac Os X Server 2026-04-16 4.6 MEDIUM N/A
AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
CVE-2005-1724 1 Apple 1 Mac Os X Server 2026-04-16 7.5 HIGH N/A
NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.
CVE-2006-0383 1 Apple 2 Mac Os X, Mac Os X Server 2026-04-16 5.0 MEDIUM N/A
IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".
CVE-2003-0424 1 Apple 1 Darwin Streaming Server 2026-04-16 5.0 MEDIUM N/A
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.
CVE-2004-0112 24 4d, Apple, Avaya and 21 more 65 Webstar, Mac Os X, Mac Os X Server and 62 more 2026-04-16 5.0 MEDIUM N/A
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
CVE-2004-0167 1 Apple 2 Mac Os X, Mac Os X Server 2026-04-16 7.5 HIGH N/A
DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.
CVE-2002-1268 1 Apple 1 Mac Os X 2026-04-16 4.6 MEDIUM N/A
Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."
CVE-2003-0051 1 Apple 2 Darwin Streaming Server, Quicktime Streaming Server 2026-04-16 5.0 MEDIUM N/A
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
CVE-2006-2238 1 Apple 1 Quicktime 2026-04-16 7.5 HIGH N/A
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue.
CVE-2000-0346 1 Apple 1 Appleshare 2026-04-16 5.0 MEDIUM N/A
AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.
CVE-2005-2743 1 Apple 3 Mac Os X, Mac Os X Server, Quicktime 2026-04-16 7.5 HIGH N/A
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
CVE-2004-2687 2 Apple, Samba 2 Xcode, Samba 2026-04-16 9.3 HIGH N/A
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
CVE-2001-0806 1 Apple 1 Mac Os X 2026-04-16 3.6 LOW N/A
Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.
CVE-2003-1413 1 Apple 2 Darwin Streaming Server, Quicktime Streaming Server 2026-04-16 4.3 MEDIUM N/A
parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
CVE-2005-1330 1 Apple 2 Mac Os X, Mac Os X Server 2026-04-16 4.9 MEDIUM N/A
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
CVE-2005-2747 1 Apple 2 Mac Os X, Mac Os X Server 2026-04-16 7.5 HIGH N/A
Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file.
CVE-2004-0824 1 Apple 1 Mac Os X 2026-04-16 2.1 LOW N/A
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.
CVE-2002-1366 2 Apple, Easy Software Products 2 Mac Os X, Cups 2026-04-16 6.2 MEDIUM N/A
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.