← Back

Iphoto

iphoto

Vendor: Apple • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Aperture
Iphoto
Apr 23, 2026
Mar 18, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7.1.2, allows remote attackers to execute arbitrary code via a crafted A...Show more
Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7.1.2, allows remote attackers to execute arbitrary code via a crafted Adobe Digital Negative (DNG) image.Show less
1Apple
1Iphoto
Apr 23, 2026
Feb 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.
1Apple
1Iphoto
Apr 23, 2026
Feb 8, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.
1Apple
1Iphoto
Apr 23, 2026
Feb 1, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple...Show more
Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.Show less
1Apple
1Iphoto
Apr 23, 2026
Jan 4, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title...Show more
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.Show less