Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-0055

EPSS 0.04% · P14
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-0055

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apple Mac OS NSFile ManagerAPI应用程序的权限提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mac OS X是苹果家族机器所使用的操作系统。 Apple 2008-002安全更新修复了Mac OS X中的多个安全漏洞,远程或本地攻击者可能利用这些漏洞造成多种威胁。 在执行递归文件拷贝操作时,NSFileManager创建了完全可写的目录,之后才限制了权限,这就造成了本地用户可以控制目录并干预之后操作的竞争条件,导致将权限提升到使用API应用程序的权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-0055

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-0055

Please Login to view more intelligence information

Same Patch Batch · n/a · 2008-03-18 · 39 CVEs total

CVE-2008-1383Gentoo ssl-cert eclass信息泄露漏洞
CVE-2008-0044Apple Mac OS AFP客户端 afp:// URL栈溢出漏洞
CVE-2008-0045Apple Mac OS AFP服务器 Kerberos主域名跨域认证漏洞
CVE-2008-0046Apple Mac OS 德语版的应用防火墙为特定服务和应用设置访问漏洞
CVE-2008-0048Apple Mac OS NSDocument API处理文件名栈溢出漏洞
CVE-2008-0049Apple Mac OS NSApplication线程mach端口任意命令执行漏洞
CVE-2008-0050Apple Safari HTTPS代理服务器可能在502 Bad Gateway安全欺骗漏洞
CVE-2008-0051Apple Mac OS CoreFoundation处理整数溢出漏洞
CVE-2008-0057Apple Mac OS 老式序列号格式的解析器多个整数溢出漏洞
CVE-2008-0997Apple Mac OS AppKit处理PPD文件栈溢出漏洞
CVE-2008-1000Apple Mac OS 服务器目录遍历漏洞
CVE-2008-1372bzip2 'bzlib.c' 未明文件全文溢出漏洞
CVE-2008-1330Novell GroupWise Windows客户端API共享文件夹邮件信息泄露漏洞
CVE-2008-1369Sun SPARC Enterprise T5120 and T5220 Servers 'sshd_config文件'不安全默认配置漏洞
CVE-2008-1370wildmary Yap Blog 'index.php' PHP远程文件包含漏洞
CVE-2008-1371Drake CMS 'install/index.php' 完全路径遍历漏洞
CVE-2008-0727IBM Informix Dynamic Server多个远程溢出漏洞
CVE-2008-0949IBM Informix Dynamic Server 畸形连接请求安全权限漏洞
CVE-2008-1368Microsoft Internet Explorer 代码注入漏洞
CVE-2008-0989Apple Mac OS mDNSResponderHelper 格式串漏洞任意指令执行漏洞

Showing top 20 of 39 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-0055

No comments yet


Leave a comment