cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 11 of 33
CVE-2009-2190P4HIGHCVSS 7.8v10.5v10.5.0+7 more2009-08-06
CVE-2009-2190 [HIGH] CWE-399 CVE-2009-2190: launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (i launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (individual service outage) by making many connections to an inetd-based launchd service.
nvd
CVE-2006-0387P4MEDIUMCVSS 6.4v10.3v10.3.1+14 more2006-03-06
CVE-2006-0387 [MEDIUM] CVE-2006-0387: Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.
nvd
CVE-2005-1725P4LOWCVSS 2.1PoCv10.4v10.4.12005-06-08
CVE-2005-1725 [LOW] CVE-2005-1725: launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files vi launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.
nvd
CVE-2009-3553P4HIGHCVSS 7.5fixed in 10.5.8≥ 10.6.0, < 10.6.22009-11-20
CVE-2009-3553 [HIGH] CWE-416 CVE-2009-3553: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly
nvd
CVE-2010-1843P4HIGHCVSS 7.8v10.6.2v10.6.3+1 more2010-11-16
CVE-2010-1843 [HIGH] CWE-20 CVE-2010-1843: Networking in Apple Mac OS X 10.6.2 through 10.6.4 allows remote attackers to cause a denial of serv Networking in Apple Mac OS X 10.6.2 through 10.6.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted PIM packet.
nvd
CVE-2009-0145P4MEDIUMCVSS 6.8v10.4.11v10.5.0+5 more2009-05-13
CVE-2009-0145 [MEDIUM] CWE-94 CVE-2009-0145: CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPho CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption.
nvd
CVE-2010-0517P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0517 [MEDIUM] CWE-119 CVE-2010-0517: Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to e Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with M-JPEG encoding, which causes QuickTime to calculate a buffer size using height and width fields, but to use a different field to control the length of
nvd
CVE-2010-0059P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0059 [MEDIUM] CWE-119 CVE-2010-0059: CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields, related to QDCA.
nvd
CVE-2005-4217P4HIGHCVSS 7.5v10.3.92005-12-14
CVE-2005-4217 [HIGH] CWE-264 CVE-2005-4217: Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.
nvd
CVE-2009-2804P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-14
CVE-2009-2804 [MEDIUM] CWE-189 CVE-2009-2804: Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windo Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.
nvd
CVE-2009-2833P4HIGHCVSS 7.5v10.5.82009-11-10
CVE-2009-2833 [HIGH] CWE-119 CVE-2009-2833: Buffer overflow in the UCCompareTextDefault API in International Components for Unicode in Apple Mac Buffer overflow in the UCCompareTextDefault API in International Components for Unicode in Apple Mac OS X 10.5.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2010-0302P4HIGHCVSS 7.5fixed in 10.5.8≥ 10.6.0, < 10.6.42010-03-05
CVE-2010-0302 [HIGH] CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, re
nvd
CVE-2011-0201P4HIGHCVSS 7.5v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0201 [HIGH] CWE-189 CVE-2011-0201: Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-depe Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.
nvd
CVE-2010-0505P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0505 [MEDIUM] CWE-119 CVE-2010-0505: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to exe Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 (JPEG2000) image, related to incorrect calculation and the CGImageReadGetBytesAtOffset function.
nvd
CVE-2007-4691P4CRITICALCVSS 10.0v10.3.9v10.4.1+9 more2007-11-15
CVE-2007-4691 [CRITICAL] CWE-264 CVE-2007-4691: The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs.
nvd
CVE-2010-3786P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3786 [MEDIUM] CWE-119 CVE-2010-3786: QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code o QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Excel file.
nvd
CVE-2014-1371P4HIGHCVSS 7.5v10.7.0v10.7.1+4 more2014-07-01
CVE-2014-1371 [HIGH] CWE-119 CVE-2014-1371: Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.
nvd
CVE-2010-1801P4MEDIUMCVSS 6.8v10.5.8v10.6.42010-08-25
CVE-2010-1801 [MEDIUM] CWE-119 CVE-2010-1801: Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attacke Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.
nvd
CVE-2011-3228P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3228 [MEDIUM] CWE-94 CVE-2011-3228: QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.
nvd
CVE-2012-0660P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0660 [MEDIUM] CWE-119 CVE-2012-0660: Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arb Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.
nvd
Apple Mac Os X Server vulnerabilities | cvebase