266511
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary file…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1027
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266512
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted docume…
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2008-1028
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266513
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial …
|
CWE-20
Improper Input Validation
|
CVE-2008-1030
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266514
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1031
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266515
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Term…
|
NVD-CWE-Other
|
CVE-2008-1032
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266516
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Per: http://cwe.mitre.org/data/definitions/184.html
'CWE-184: Incomplete Blacklist'
|
NVD-CWE-Other
|
CVE-2008-1032
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266517
|
- |
|
apple
|
cups
|
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1033
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266518
|
- |
|
apple
|
mac_os_x
|
Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted help:topic URL that tri…
|
CWE-189
Numeric Errors
|
CVE-2008-1034
|
2017-08-8 10:29 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266519
|
- |
|
plume-cms
|
plume_cms
|
Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1048
|
2017-08-8 10:29 |
2008-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266520
|
- |
|
positive_software
|
h-sphere sitestudio
|
Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-1049
|
2017-08-8 10:29 |
2008-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|