nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.
CVE Status: Modified
No CVSS data available
Exploit-db Github