Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 10 of 33
CVE-2009-0943P4MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0943 [MEDIUM] CWE-20 CVE-2009-0943: Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.
nvd
CVE-2010-0055P4CRITICALCVSS 10.0v10.5.82010-03-30
CVE-2010-0055 [CRITICAL] CVE-2010-0055: xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers t
xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified package.
nvd
CVE-2009-0152P4HIGHCVSS 7.5≥ 10.5.0, < 10.5.72009-05-13
CVE-2009-0152 [HIGH] CWE-312 CVE-2009-0152: iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communicatio
iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2011-0200P4MEDIUMCVSS 6.8v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0200 [MEDIUM] CWE-189 CVE-2011-0200: Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arb
Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.
nvd
CVE-2007-4700P4HIGHCVSS 7.5v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4700 [HIGH] CWE-264 CVE-2007-4700: Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers t
Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.
nvd
CVE-2011-0205P3MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0205 [MEDIUM] CWE-119 CVE-2011-0205: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to exe
Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.
nvd
CVE-2014-4350P4MEDIUMCVSS 6.8v10.7.52014-09-19
CVE-2014-4350 [MEDIUM] CWE-119 CVE-2014-4350: Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execut
Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.
nvd
CVE-2008-0054P4MEDIUMCVSS 6.4v10.4.112008-03-18
CVE-2008-0054 [MEDIUM] CWE-20 CVE-2008-0054: Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary co
Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.
nvd
CVE-2010-0508P4CRITICALCVSS 10.0≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0508 [CRITICAL] CVE-2010-0508: Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mai
Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attack vectors.
nvd
CVE-2004-1088P4HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-02
CVE-2004-1088 [HIGH] CVE-2004-1088: Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
nvd
CVE-2010-3798P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3798 [MEDIUM] CWE-119 CVE-2010-3798: Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to
Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive.
nvd
CVE-2010-1836P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1836 [MEDIUM] CWE-119 CVE-2010-1836: Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows
Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2010-1808P4MEDIUMCVSS 6.8v10.5.8v10.6.42010-08-25
CVE-2010-1808 [MEDIUM] CWE-119 CVE-2010-1808: Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows
Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
nvd
CVE-2014-1256P4HIGHCVSS 7.5v10.7.0v10.7.1+4 more2014-02-27
CVE-2014-1256 [HIGH] CWE-119 CVE-2014-1256: Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
nvd
CVE-2011-3437P4MEDIUMCVSS 6.8v10.7.0v10.7.12011-10-14
CVE-2011-3437 [MEDIUM] CWE-189 CVE-2011-3437: Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows re
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
nvd
CVE-2010-4010P4MEDIUMCVSS 6.8v10.5.82010-11-16
CVE-2010-4010 [MEDIUM] CWE-189 CVE-2010-4010: Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attacke
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.
nvd
CVE-2010-1837P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1837 [MEDIUM] CWE-119 CVE-2010-1837: CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitr
CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a PDF document.
nvd
CVE-2010-1833P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1833 [MEDIUM] CWE-119 CVE-2010-1833: Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute
Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.
nvd
CVE-2009-2812P4MEDIUMCVSS 6.8v10.5.82009-09-14
CVE-2009-2812 [MEDIUM] CVE-2009-2812: Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifi
Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site.
nvd
CVE-2010-1637P4MEDIUMCVSS 6.5fixed in 10.6.82010-06-22
CVE-2010-1637 [MEDIUM] CWE-918 CVE-2010-1637: The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass
The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.
nvd