CVE-2005-1721
Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.
CVEs:CVE-2005-1721
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| afp_server | affected | apple | — | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.
CVEs:CVE-2005-1721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| afp_server | affected | apple | — | — |
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.
CVEs:CVE-2005-1933
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.
CVEs:CVE-2005-1724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x_server | affected | apple | — | — |
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
CVEs:CVE-2005-1474
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsafe types, which could allow atta...
CVEs:CVE-2005-1723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x_server | affected | apple | — | — |
launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.
CVEs:CVE-2005-1725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x_server | affected | apple | — | — |
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.
CVEs:CVE-2005-1722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.
CVEs:CVE-2005-1473
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
AFP Server for Mac OS X 10.4.1, when using an ACL enabled volume, does not properly remove an ACL when a file is copied to a directory that does not use ACLs, which will override the POSIX file permissions for that ACL.
CVEs:CVE-2005-1720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| afp_server | affected | apple | — | — |
MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.
CVEs:CVE-2005-1728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."
CVEs:CVE-2005-1727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x_server | affected | apple | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.