← Back

Mac Os X

mac_os_x

Vendor: Apple • 3,210 CVEs

CVEs (3,210)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
Apr 23, 2026
Nov 28, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 27, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 27, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as...Show more
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 27, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 22, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which trigge...Show more
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 22, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity o...Show more
com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity of this issue has been disputed by a third party, who states that the impact is limited to a denial of service (kernel panic) due to a vm_fault call with a non-aligned address.Show less
1Apple
1Mac Os X
Apr 23, 2026
Nov 21, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression.
2Apple
Opendarwin
2Darwin Kernel
Mac Os X
Apr 23, 2026
Nov 4, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response fram...Show more
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow.Show less
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo paren...Show more
User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, when such an operation is not actually supported, which could result in less secure password management than intended.Show less
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might...Show more
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access to the original user's Kerberos tickets.Show less
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in QuickDraw Manager in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows context-dependent attackers to cause a denial of service ("memory corruption" and crash) via a crafted PICT image tha...Show more
Unspecified vulnerability in QuickDraw Manager in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows context-dependent attackers to cause a denial of service ("memory corruption" and crash) via a crafted PICT image that is not properly handled by a certain "unsupported QuickDraw operation."Show less
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without GUIds to bypass service access controls and log into the system using loginwindow via unknown vectors.
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
3.7 LOW· v2
Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.
2Apple
Next
2Mac Os X
Openstep
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child...Show more
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.Show less
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Apple ImageIO on Apple Mac OS X 10.4 through 10.4.7 allows remote attackers to execute arbitrary code via a malformed JPEG2000 image.
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when...Show more
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site's identity cannot be trusted.Show less
1Apple
1Mac Os X
Apr 23, 2026
Oct 3, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appser...Show more
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows the user to manage WebObjects applications.Show less
3Apple
DebianOpenbsd
4Debian Linux
Mac Os XMac Os X Server+1 more
Apr 23, 2026
Sep 27, 2006
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead...Show more
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Sep 21, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless softw...Show more
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted frames.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Sep 21, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted fra...Show more
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates.Show less