Advisories
OtherActive exploitation (sightings)CRITICAL2005-01-19
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
CVEs:CVE-2005-0043
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2005-01-29
ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.
CVEs:CVE-2005-0126
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2005-01-29
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
CVEs:CVE-2005-0127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2005-01-20
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
CVEs:CVE-2005-1332
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2005-01-03
Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.
CVEs:CVE-2005-0289
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| airport_express |
affected |
apple |
— |
— |
| airport_extreme |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2005-01-20
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
CVEs:CVE-2005-1343
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2005-01-20
Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.
CVEs:CVE-2005-1336
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2005-01-20
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
CVEs:CVE-2005-0594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2005-01-11
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
CVEs:CVE-2005-1335
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2005-01-29
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argum...
CVEs:CVE-2005-0125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |