Apple Security Advisories · February 2008 — Apple Security Advisories
12 advisories 12 CVEs

Apple-vendor CVEs for 2008-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-0778

OtherPoC exploitCRITICAL2008-02-14

Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, ...

CVEs:CVE-2008-0778

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-0729

iOSEPSS <= 49%CRITICAL2008-02-12

Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs a long string and an array containing long string elements, possibly a r...

CVEs:CVE-2008-0729

Affected products

ProductStatusVendorPackageEcosystem
mobile_safari affected apple
Upstream advisory

CVE-2008-0040

macOSEPSS <= 49%HIGH2008-02-12

Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via unknown vectors related to mbuf chains that trigger memory corruption.

CVEs:CVE-2008-0040

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2008-0042

macOSEPSS <= 49%CRITICAL2008-02-12

Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arbitrary code via unspecified URL schemes.

CVEs:CVE-2008-0042

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2008-5286

OtherEPSS <= 49%CRITICAL2008-02-21

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.

CVEs:CVE-2008-5286

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2008-0043

OtherEPSS <= 49%HIGH2008-02-07

Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.

CVEs:CVE-2008-0043

Affected products

ProductStatusVendorPackageEcosystem
iphoto affected apple
Upstream advisory

CVE-2008-0039

macOSEPSS <= 49%CRITICAL2008-02-12

Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.

CVEs:CVE-2008-0039

Affected products

ProductStatusVendorPackageEcosystem
mail affected apple
Upstream advisory

CVE-2008-0830

OtherEPSS <= 49%HIGH2008-02-19

The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.

CVEs:CVE-2008-0830

Affected products

ProductStatusVendorPackageEcosystem
iphoto affected apple
Upstream advisory

CVE-2008-0041

macOSEPSS <= 49%MEDIUM2008-02-12

Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running Parental Controls.

CVEs:CVE-2008-0041

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2008-0037

macOSEPSS <= 49%MEDIUM2008-02-12

X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the "Allow connections from network client" preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server.

CVEs:CVE-2008-0037

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2008-0894

SafariEPSS <= 49%HIGH2008-02-21

Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitmap (BMP) or (2) GIF file, a related issue to CVE-2008-0420.

CVEs:CVE-2008-0894

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2008-0038

macOSEPSS <= 49%LOW2008-02-12

Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.

CVEs:CVE-2008-0038

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.