← Back

Mac Os X

mac_os_x

Vendor: Apple • 3,210 CVEs

CVEs (3,210)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apple
OpensslOracle
5Application Server
Corporate Time Outlook ConnectorHttp Server+2 more
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
3Apple
OpensslOracle
5Application Server
Corporate Time Outlook ConnectorHttp Server+2 more
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
3Apple
OpensslOracle
5Application Server
Corporate Time Outlook ConnectorHttp Server+2 more
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbit...Show more
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.Show less
1Apple
1Mac Os X
Apr 16, 2026
Jul 11, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS...Show more
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.Show less
1Apple
1Mac Os X
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.
1Apple
1Mac Os X
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
3.6 LOW· v2
Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.
1Apple
1Mac Os X
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decodi...Show more
Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.Show less
1Apple
1Mac Os X
Apr 16, 2026
Oct 17, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root priv...Show more
NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges.Show less
1Apple
1Mac Os X
Apr 16, 2026
Sep 11, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.
11Apple
CiscoHp+8 more
14Aix
BsdosHp Ux+11 more
May 28, 2026
Aug 1, 1997
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.