cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 1 of 33
CVE-2003-0694P2CRITICALCVSS 10.0ExploitedPoCv10.2v10.2.1+5 more2003-10-06
CVE-2003-0694 [CRITICAL] CVE-2003-0694: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
nvd
CVE-2003-0681P2HIGHCVSS 7.5ExploitedPoCv10.2v10.2.1+5 more2003-10-06
CVE-2003-0681 [HIGH] CVE-2003-0681: A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rul A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
nvd
CVE-2007-3798P2CRITICALCVSS 9.8PoC≥ 10.0.0, < 10.4.112007-07-16
CVE-2007-3798 [CRITICAL] CWE-252 CVE-2007-3798: Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote atta Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
nvd
CVE-2010-1205P2CRITICALCVSS 9.8PoC≥ 10.6.0, < 10.6.42010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2003-0466P3CRITICALCVSS 9.8PoCv10.2.62003-08-27
CVE-2003-0466 [CRITICAL] CWE-193 CVE-2003-0466: Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may al Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU
nvd
CVE-2010-0211P2CRITICALCVSS 9.8PoC≥ 10.6.0, < 10.6.52010-07-28
CVE-2010-0211 [CRITICAL] CWE-252 CVE-2010-0211: The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a ca The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an
nvd
CVE-2013-0984P2CRITICALCVSS 9.3PoC≤ 10.6.8v10.0+64 more2013-06-05
CVE-2013-0984 [CRITICAL] CWE-119 CVE-2013-0984: Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message.
nvd
CVE-2007-5863P3CRITICALCVSS 9.3PoCv10.5.12007-12-19
CVE-2007-5863 [CRITICAL] CWE-310 CVE-2007-5863: Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the client and the server, using a modified distribution definition file with the "allow-external-scripts" option.
nvd
CVE-2010-1119P3CRITICALCVSS 10.0PoCv10.5.0v10.5.1+12 more2010-03-25
CVE-2010-1119 [CRITICAL] CWE-399 CVE-2010-1119: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute man
nvd
CVE-2006-1982P3HIGHCVSS 7.5PoCv10.3v10.3.1+14 more2006-04-21
CVE-2006-1982 [HIGH] CWE-119 CVE-2006-1982: Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in app Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.
nvd
CVE-2004-0430P3MEDIUMCVSS 5.1PoC≤ 10.3.32004-07-07
CVE-2004-0430 [MEDIUM] CVE-2004-0430: Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attacke Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.
nvd
CVE-2009-1236P3CRITICALCVSS 10.0PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1236 [CRITICAL] CWE-119 CVE-2009-1236: Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple M Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.
nvd
CVE-2009-0949P3HIGHCVSS 7.5PoC≥ 10.0.0, < 10.4.11≥ 10.5.0, < 10.5.82009-06-09
CVE-2009-0949 [HIGH] CWE-908 CVE-2009-0949: The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize mem The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
nvd
CVE-2010-1840P3HIGHCVSS 7.5PoCv10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1840 [HIGH] CWE-119 CVE-2010-1840: Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2007-0117P3CRITICALCVSS 10.0PoCv10.4.82007-01-09
CVE-2007-0117 [CRITICAL] CVE-2007-0117: DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly valida DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.
nvd
CVE-2006-0848P3MEDIUMCVSS 5.1PoCv10.4.52006-02-22
CVE-2006-0848 [MEDIUM] CWE-16 CVE-2006-0848: The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assi The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file th
nvd
CVE-2007-1071P3HIGHCVSS 7.8PoCv10.4.82007-02-22
CVE-2007-1071 [HIGH] CVE-2007-1071: Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote at Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression. NOTE: this is a different issue than CVE-2006-3502 and CVE-2006-3503.
nvd
CVE-2006-0395P3MEDIUMCVSS 5.1PoCv10.4.52006-08-05
CVE-2006-0395 [MEDIUM] CVE-2006-0395: The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types t The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.
nvd
CVE-2010-0520P3MEDIUMCVSS 6.8PoCv10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0520 [MEDIUM] CWE-119 CVE-2010-0520: Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 al Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI chunks and untrusted length values in a .fli file, which are not properly handled during decompression.
nvd
CVE-2008-5183P3HIGHCVSS 7.5PoCfixed in 10.5.62008-11-21
CVE-2008-5183 [HIGH] CWE-476 CVE-2008-5183: cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
nvd
1 / 33Next →
Apple Mac Os X Server vulnerabilities | cvebase