Are there any security vulnerabilities that would allow an attacker to change the admin password

administratorNetworkSecurity

A good friend of mine woke up one day to discover that someone had changed the admin password on his mac. It seems the same attacker also broke into his Yahoo email. Assuming he was on an unsecured network is there some kind of Mac OS X vulnerability that would allow an attacker to login remotely and change the admin password, even if remote management and remote login were disabled? How could someone without physical access to the machine do this?

Best Answer

CVEdetails.com currently lists 783 vulnerabilities in Mac OS X, of which over 100 allow remote attacks, and many allow Admin access to be gained.

If you do want to ask about specifics, http://security.stackexchange.com welcomes a wide range of security questions.