← Back

Mac Os X

mac_os_x

Vendor: Apple • 3,210 CVEs

CVEs (3,210)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
3Imageio
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.
1Apple
3Carboncore
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive in...Show more
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
1Apple
3Applescript
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifi...Show more
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
4.9 MEDIUM· v2
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-...Show more
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.Show less
1Apple
3Iphone Os
Mac Os XMac Os X Server
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (me...Show more
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.Show less
2Apple
Freebsd
2Freebsd
Mac Os X
Apr 29, 2026
Mar 4, 2011
N/A· v4
N/A· v3
1.9 LOW· v2
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum compar...Show more
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of files via two symlink attacks on /tmp/crontab.XXXXXXXXXX temporary files.Show less
4Apple
FreebsdNetbsd+1 more
4Freebsd
Mac Os XNetbsd+1 more
Apr 29, 2026
Mar 2, 2011
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consump...Show more
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.Show less
1Apple
1Mac Os X
Apr 29, 2026
Jan 25, 2011
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Apple Mac OS X does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as d...Show more
Apple Mac OS X does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Jan 10, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to intera...Show more
Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to interaction between Software Update and distribution scripts.Show less
10Apache
AppleDebian+7 more
17Chrome
Debian LinuxEnterprise Linux Desktop+14 more
Apr 29, 2026
Dec 7, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impac...Show more
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.Show less
9Apache
AppleCanonical+6 more
15Chrome
Debian LinuxEnterprise Linux Desktop+12 more
Apr 29, 2026
Nov 17, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows con...Show more
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DO...Show more
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.Show less