Apple Iphoto vulnerabilities

5 known vulnerabilities affecting apple/iphoto.

Total CVEs
5
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2008-0987MEDIUMCVSS 6.8v7.1.22008-03-18
CVE-2008-0987 [MEDIUM] CWE-119 CVE-2008-0987: Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibil Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7.1.2, allows remote attackers to execute arbitrary code via a crafted Adobe Digital Negative (DNG) image.
nvd
CVE-2008-0830HIGHCVSS 7.5PoCv4.0.32008-02-19
CVE-2008-0830 [HIGH] CVE-2008-0830: The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.
nvd
CVE-2008-0043CRITICALCVSS 9.3≤ 7.12008-02-08
CVE-2008-0043 [CRITICAL] CWE-94 CVE-2008-0043: Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrar Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.
nvd
CVE-2007-0645MEDIUMCVSS 6.8PoCv6.0.52007-02-01
CVE-2007-0645 [MEDIUM] CVE-2007-0645: Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.
nvd
CVE-2007-0051MEDIUMCVSS 6.8PoCv6.0.52007-01-04
CVE-2007-0051 [MEDIUM] CWE-134 CVE-2007-0051: Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows rem Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
nvd