Severity
7.8HIGHNVD
EPSS
0.6%
top 31.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateNov 12

Description

The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.

CVSS vector

AV:N/AC:L/C:C/I:N/A:NExploitability: 10.0 | Impact: 6.9

Affected Packages3 packages

NVDapple/mac_os_x_server10.4.11, 10.5.6+1
NVDapple/mac_os_x10.4.11, 10.5.6+1
Linuxlinux/linux_kernel6.7.06.12.53+2

🔴Vulnerability Details

4
OSV
iommu/vt-d: debugfs: Fix legacy mode page table dump logic2025-11-12
OSV
btrfs: call __btrfs_remove_free_space_cache_locked on cache load failure2025-10-22
GHSA
GHSA-2xg8-j8mx-hw4m: The Remote Apple Events server in Apple Mac OS X 102022-05-02
CVEList
CVE-2009-0018: The Remote Apple Events server in Apple Mac OS X 102009-02-13

📋Vendor Advisories

4
Red Hat
kernel: iommu/vt-d: debugfs: Fix legacy mode page table dump logic2025-11-12
Red Hat
kernel: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=02025-06-18
Red Hat
kernel: media: ts2020: fix null-ptr-deref in ts2020_probe()2024-12-27
Red Hat
kernel: btrfs: do not BUG_ON in link_to_fixup_dir2024-03-25

💬Community

1
Bugzilla
CVE-2009-1189 dbus: invalid fix for CVE-2008-38342009-04-20
CVE-2009-0018 — Apple MAC OS X vulnerability | cvebase