Apple Security Advisories · February 2005 — Apple Security Advisories
4 advisories 4 CVEs

Apple-vendor CVEs for 2005-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2005-0340

OtherEPSS <= 49%HIGH2005-02-10

Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.

CVEs:CVE-2005-0340

Affected products

ProductStatusVendorPackageEcosystem
afp_server affected apple
Upstream advisory

CVE-2005-0234

SafariEPSS <= 49%MEDIUM2005-02-07

The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character set...

CVEs:CVE-2005-0234

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2005-0341

SafariEPSS <= 49%CRITICAL2005-02-10

Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.

CVEs:CVE-2005-0341

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2005-0342

macOSEPSS <= 49%MEDIUM2005-02-10

The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.

CVEs:CVE-2005-0342

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.