← Back

Apple

apple

8,695 CVEs • 196 products

Products (196)

Click to collapse
Toggle
Iphone Os
iphone_os
Mac Os X
mac_os_x
Macos
macos
Tvos
tvos
Ipados
ipados
Watchos
watchos
Safari
safari
Itunes
itunes
Icloud
icloud
Visionos
visionos
Webkit
webkit
Quicktime
quicktime
Xcode
xcode
Ipad Os
ipad_os
Cups
cups
Apple Tv
apple_tv
Ipod Touch
ipod_touch
Os X Server
os_x_server
Swiftnio
swiftnio
Iphone
iphone
Garageband
garageband
Ichat
ichat
Imageio
imageio
Music
music
Keynote
keynote
Pages
pages
Tv Os
tv_os
Mail
mail
Iphoto
iphoto
Cfnetwork
cfnetwork
Terminal
terminal
Afp Server
afp_server
Time Capsule
time_capsule
Numbers
numbers
Iwork
iwork
Swift
swift
Webobjects
webobjects
Ical
ical
Webcore
webcore
Mdnsresponder
mdnsresponder
Coregraphics
coregraphics
Bonjour
bonjour
Watch Os
watch_os
Logic Pro X
logic_pro_x
Mac Os
mac_os
Appleshare
appleshare
Applescript
applescript
Xsan
xsan
Installer
installer
Imovie
imovie
A Ux
a_ux
Carboncore
carboncore
Java 1.5
java_1.5
Java 1.6
java_1.6
Ipad2
ipad2
Ichat Server
ichat_server
Boot Camp
boot_camp
Apple Support
apple_support
Shortcuts
shortcuts
Shazam
shazam
Files
files
Container
container
Claris Emailer
claris_emailer
802.11n
Ichat Av
ichat_av
Airport Card
airport_card
Weblog Server
weblog_server
Textedit
textedit
Preview
preview
Server Manager
server_manager
Pdfkit
pdfkit

CVEs (8,695)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
Apr 16, 2026
May 12, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.
1Apple
2Mac Os X
Terminal
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.
1Apple
3Mac Os X
Mac Os X ServerTerminal
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
1Apple
1Mac Os X
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
1Apple
1Mac Os X
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
1Apple
1Mac Os X
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
1Apple
1Mac Os X
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the...Show more
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.Show less
1Apple
3Applescript
Mac Os XMac Os X Server
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attacke...Show more
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
4.9 MEDIUM· v2
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
1Apple
1Mac Os X Server
Apr 16, 2026
May 4, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 3, 2005
N/A· v4
N/A· v3
3.6 LOW· v2
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
1Apple
1Safari
Apr 16, 2026
May 3, 2005
N/A· v4
N/A· v3
2.6 LOW· v2
Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 3, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
1Apple
1Quicktime Pictureviewer
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.
3Apple
HmdtOmnigroup
3Omniweb
SafariShiira
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated us...Show more
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.Show less
2Apple
Opendarwin
3Darwin Kernel
Mac Os XMac Os X Server
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of ser...Show more
Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of service (CPU consumption) via a crafted mach-o header.Show less