Apple Security Advisories · March 2010 — Apple Security Advisories
84 advisories 84 CVEs

Apple-vendor CVEs for 2010-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-0520

macOSWeaponized exploitCRITICAL2010-03-30

Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI ch...

CVEs:CVE-2010-0520

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0519

macOSWeaponized exploitCRITICAL2010-03-30

Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles fie...

CVEs:CVE-2010-0519

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0046

SafariWeaponized exploitHIGH2010-03-12

The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments.

CVEs:CVE-2010-0046

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1029

iOSActive exploitation (sightings)CRITICAL2010-03-19

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (appl...

CVEs:CVE-2010-1029

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1179

iOSActive exploitation (sightings)HIGH2010-03-26

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a...

CVEs:CVE-2010-1179

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1176

iOSActive exploitation (sightings)HIGH2010-03-26

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in...

CVEs:CVE-2010-1176

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1180

iOSActive exploitation (sightings)HIGH2010-03-26

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514.

CVEs:CVE-2010-1180

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1177

iOSActive exploitation (sightings)HIGH2010-03-26

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.

CVEs:CVE-2010-1177

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1131

SafariActive exploitation (sightings)HIGH2010-03-26

JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the <object> substring.

CVEs:CVE-2010-1131

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1119

macOSPoC exploitHIGH2010-03-25

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of servic...

CVEs:CVE-2010-1119

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
mac_os_x_server affected apple
safari affected apple
Upstream advisory

CVE-2010-0962

OtherPoC exploitMEDIUM2010-03-04

The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for a...

CVEs:CVE-2010-0962

Affected products

ProductStatusVendorPackageEcosystem
airport_express affected apple
airport_extreme affected apple
time_capsule affected apple
Upstream advisory

CVE-2010-0511

macOSPoC exploitMEDIUM2010-03-30

Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast Composer workflow when this workflow is overwritten, which allows attackers to access a workflow via unspecified vectors.

CVEs:CVE-2010-0511

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0393

OtherPoC exploitMEDIUM2010-03-03

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file...

CVEs:CVE-2010-0393

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2010-0529

OtherEPSS <= 49%HIGH2010-03-31

Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted ...

CVEs:CVE-2010-0529

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-0050

SafariEPSS <= 49%HIGH2010-03-12

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.

CVEs:CVE-2010-0050

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2010-0049

SafariEPSS <= 49%HIGH2010-03-12

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.

CVEs:CVE-2010-0049

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0040

SafariEPSS <= 49%HIGH2010-03-12

Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a h...

CVEs:CVE-2010-0040

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0052

SafariEPSS <= 49%HIGH2010-03-12

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "callbacks for HTML elements."

CVEs:CVE-2010-0052

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0053

SafariEPSS <= 49%HIGH2010-03-12

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.

CVEs:CVE-2010-0053

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0054

SafariEPSS <= 49%HIGH2010-03-12

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML IMG elements.

CVEs:CVE-2010-0054

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0528

OtherEPSS <= 49%HIGH2010-03-31

Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample de...

CVEs:CVE-2010-0528

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-0043

SafariEPSS <= 49%HIGH2010-03-12

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.

CVEs:CVE-2010-0043

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1120

macOSEPSS <= 49%HIGH2010-03-25

Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Charlie Miller during a Pwn2Own competition at CanSecWest 2010.

CVEs:CVE-2010-1120

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0047

SafariEPSS <= 49%HIGH2010-03-12

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."

CVEs:CVE-2010-0047

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0048

SafariEPSS <= 49%HIGH2010-03-12

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.

CVEs:CVE-2010-0048

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0526

macOSEPSS <= 49%CRITICAL2010-03-30

Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPEG ...

CVEs:CVE-2010-0526

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0517

macOSEPSS <= 49%CRITICAL2010-03-30

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with M-JPEG encoding, which causes QuickTime to calculat...

CVEs:CVE-2010-0517

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0516

macOSEPSS <= 49%CRITICAL2010-03-30

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding, which triggers memory corruption when...

CVEs:CVE-2010-0516

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0059

macOSEPSS <= 49%CRITICAL2010-03-30

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inc...

CVEs:CVE-2010-0059

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0045

SafariEPSS <= 49%HIGH2010-03-12

Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.

CVEs:CVE-2010-0045

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0205

OtherEPSS <= 49%HIGH2010-03-02

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which a...

CVEs:CVE-2010-0205

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2010-0505

macOSEPSS <= 49%CRITICAL2010-03-30

Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 (JPEG2000) image, related to incorrect calculation and the CGImag...

CVEs:CVE-2010-0505

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0527

OtherEPSS <= 49%HIGH2010-03-31

Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.

CVEs:CVE-2010-0527

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-0536

OtherEPSS <= 49%HIGH2010-03-31

Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.

CVEs:CVE-2010-0536

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-0062

macOSEPSS <= 49%CRITICAL2010-03-30

Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encodin...

CVEs:CVE-2010-0062

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0513

macOSEPSS <= 49%CRITICAL2010-03-30

Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PostScript document.

CVEs:CVE-2010-0513

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0514

macOSEPSS <= 49%CRITICAL2010-03-30

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.261 encoding.

CVEs:CVE-2010-0514

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0504

macOSEPSS <= 49%CRITICAL2010-03-30

Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2010-0504

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0501

macOSEPSS <= 49%MEDIUM2010-03-30

Directory traversal vulnerability in FTP Server in Apple Mac OS X Server before 10.6.3 allows remote authenticated users to read arbitrary files via crafted filenames.

CVEs:CVE-2010-0501

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0506

macOSEPSS <= 49%CRITICAL2010-03-30

Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted NEF image.

CVEs:CVE-2010-0506

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0507

macOSEPSS <= 49%CRITICAL2010-03-30

Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PEF image.

CVEs:CVE-2010-0507

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0518

macOSEPSS <= 49%CRITICAL2010-03-30

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with Sorenson encoding.

CVEs:CVE-2010-0518

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0060

macOSEPSS <= 49%CRITICAL2010-03-30

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.

CVEs:CVE-2010-0060

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0515

macOSEPSS <= 49%CRITICAL2010-03-30

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with H.264 encoding.

CVEs:CVE-2010-0515

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0051

SafariEPSS <= 49%HIGH2010-03-12

WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document. NOTE: this might overlap CVE-2010-0651.

CVEs:CVE-2010-0051

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0302

OtherEPSS <= 49%CRITICAL2010-03-03

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial ...

CVEs:CVE-2010-0302

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1181

iOSEPSS <= 49%CRITICAL2010-03-29

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a MARQUEE element.

CVEs:CVE-2010-1181

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-0056

macOSEPSS <= 49%CRITICAL2010-03-30

Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.

CVEs:CVE-2010-0056

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0497

macOSEPSS <= 49%CRITICAL2010-03-30

Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected warning for an unsafe file type in an internet enabled disk image, which makes it easier for user-assisted remote attackers to execute arbitrary code via a package file type.

CVEs:CVE-2010-0497

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0041

SafariEPSS <= 49%HIGH2010-03-12

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted ...

CVEs:CVE-2010-0041

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0042

SafariEPSS <= 49%HIGH2010-03-12

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted ...

CVEs:CVE-2010-0042

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0065

macOSEPSS <= 49%CRITICAL2010-03-30

Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image with bzip2 compression.

CVEs:CVE-2010-0065

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0510

macOSEPSS <= 49%HIGH2010-03-30

Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users to obtain login access via an expired password.

CVEs:CVE-2010-0510

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0522

macOSEPSS <= 49%HIGH2010-03-30

Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which allows remote authenticated users to leverage this former membership to obtain a server connection via ...

CVEs:CVE-2010-0522

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0503

macOSEPSS <= 49%HIGH2010-03-30

Use-after-free vulnerability in iChat Server in Apple Mac OS X Server 10.5.8 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2010-0503

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0055

macOSEPSS <= 49%HIGH2010-03-30

xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified package.

CVEs:CVE-2010-0055

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0531

OtherEPSS <= 49%HIGH2010-03-31

Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.

CVEs:CVE-2010-0531

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2009-2801

macOSEPSS <= 49%MEDIUM2010-03-30

The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass intended access restrictions via packet data, related to a "timing issue."

CVEs:CVE-2009-2801

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0521

macOSEPSS <= 49%CRITICAL2010-03-30

Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.

CVEs:CVE-2010-0521

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1126

SafariEPSS <= 49%MEDIUM2010-03-26

The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.

CVEs:CVE-2010-1126

Affected products

ProductStatusVendorPackageEcosystem
webkit affected apple
Upstream advisory

CVE-2010-0500

macOSEPSS <= 49%HIGH2010-03-30

Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection is...

CVEs:CVE-2010-0500

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0512

macOSEPSS <= 49%HIGH2010-03-30

The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access...

CVEs:CVE-2010-0512

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0523

macOSEPSS <= 49%HIGH2010-03-30

Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java applet.

CVEs:CVE-2010-0523

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0058

macOSEPSS <= 49%MEDIUM2010-03-30

freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.plist ProgramArguments key and consequently does not run, which might allow remote attackers to introduce viruses into the system.

CVEs:CVE-2010-0058

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0063

macOSEPSS <= 49%CRITICAL2010-03-30

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list o...

CVEs:CVE-2010-0063

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0508

macOSEPSS <= 49%HIGH2010-03-30

Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attack vectors.

CVEs:CVE-2010-0508

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2009-2822

OtherEPSS <= 49%MEDIUM2010-03-31

AirPort Utility before 5.5.1 for Apple AirPort Base Station does not properly distribute MAC address ACLs to network extenders, which allows remote attackers to bypass intended access restrictions via an 802.11 authentication frame.

CVEs:CVE-2009-2822

Affected products

ProductStatusVendorPackageEcosystem
airport_utility affected apple
Upstream advisory

CVE-2010-0533

macOSEPSS <= 49%HIGH2010-03-30

Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and modify files in that directory, via unspecified vectors.

CVEs:CVE-2010-0533

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0044

SafariEPSS <= 49%MEDIUM2010-03-12

PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.

CVEs:CVE-2010-0044

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1178

iOSEPSS <= 49%HIGH2010-03-29

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinitely long string.

CVEs:CVE-2010-1178

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0535

macOSEPSS <= 49%HIGH2010-03-30

Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions vi...

CVEs:CVE-2010-0535

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0537

macOSEPSS <= 49%LOW2010-03-30

DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a crafted...

CVEs:CVE-2010-0537

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0524

macOSEPSS <= 49%HIGH2010-03-30

The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a craf...

CVEs:CVE-2010-0524

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0502

macOSEPSS <= 49%MEDIUM2010-03-30

iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform logging for all types of messages, which might allow remote attackers to avoid message auditing via an unspecified selection of message type.

CVEs:CVE-2010-0502

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1099

SafariEPSS <= 49%CRITICAL2010-03-24

Integer overflow in Apple Safari allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.

CVEs:CVE-2010-1099

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0057

macOSEPSS <= 49%HIGH2010-03-30

AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request.

CVEs:CVE-2010-0057

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0925

SafariEPSS <= 49%HIGH2010-03-03

cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the SRC attribute of a (1) IMG or (2) IFRAME element.

CVEs:CVE-2010-0925

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0924

SafariEPSS <= 49%HIGH2010-03-03

cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.

CVEs:CVE-2010-0924

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-0534

macOSEPSS <= 49%HIGH2010-03-30

Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.

CVEs:CVE-2010-0534

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0525

macOSEPSS <= 49%CRITICAL2010-03-30

Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive inf...

CVEs:CVE-2010-0525

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0509

macOSEPSS <= 49%HIGH2010-03-30

SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership during access to the home directories of user accounts.

CVEs:CVE-2010-0509

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0064

macOSEPSS <= 49%MEDIUM2010-03-30

DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by othe...

CVEs:CVE-2010-0064

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0498

macOSEPSS <= 49%HIGH2010-03-30

Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.

CVEs:CVE-2010-0498

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0532

OtherEPSS <= 49%MEDIUM2010-03-31

Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.

CVEs:CVE-2010-0532

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.