cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 12 of 33
CVE-2010-0501P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0501 [MEDIUM] CWE-22 CVE-2010-0501: Directory traversal vulnerability in FTP Server in Apple Mac OS X Server before 10.6.3 allows remote Directory traversal vulnerability in FTP Server in Apple Mac OS X Server before 10.6.3 allows remote authenticated users to read arbitrary files via crafted filenames.
nvd
CVE-2011-0224P4MEDIUMCVSS 6.8≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-0224 [MEDIUM] CWE-94 CVE-2011-0224: CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or caus CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.
nvd
CVE-2011-3217P4MEDIUMCVSS 6.8≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3217 [MEDIUM] CWE-119 CVE-2011-3217: MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.
nvd
CVE-2013-0975P4MEDIUMCVSS 6.8v10.7.0v10.7.1+4 more2013-06-05
CVE-2013-0975 [MEDIUM] CWE-119 CVE-2013-0975: Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to exec Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
nvd
CVE-2011-0179P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0179 [MEDIUM] CWE-119 CVE-2011-0179: CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.
nvd
CVE-2014-1370P4MEDIUMCVSS 6.8v10.7.0v10.7.1+4 more2014-07-01
CVE-2014-1370 [MEDIUM] CWE-119 CVE-2014-1370: The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.
nvd
CVE-2011-0174P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0174 [MEDIUM] CWE-119 CVE-2011-0174: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remot Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
nvd
CVE-2005-2747P4HIGHCVSS 7.5v10.4.22005-10-25
CVE-2005-2747 [HIGH] CVE-2005-2747: Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Sa Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file.
nvd
CVE-2006-1469P4HIGHCVSS 7.5v10.4v10.4.1+5 more2006-06-27
CVE-2006-1469 [HIGH] CWE-119 CVE-2006-1469: Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.
nvd
CVE-2010-0036P4HIGHCVSS 7.8v10.5.8v10.6.22010-01-20
CVE-2010-0036 [HIGH] CWE-119 CVE-2010-0036: Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.
nvd
CVE-2007-0719P4MEDIUMCVSS 6.8v10.3.9v10.4+8 more2007-03-13
CVE-2007-0719 [MEDIUM] CVE-2007-0719: Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assi Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.
nvd
CVE-2005-0373P4HIGHCVSS 7.5v10.0v10.1+23 more2004-10-07
CVE-2005-0373 [HIGH] CVE-2005-0373: Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
nvd
CVE-2004-0079P4HIGHCVSS 7.5v10.3.32004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2005-0126P4HIGHCVSS 7.5v10.2.8v10.3.72005-05-02
CVE-2005-0126 [HIGH] CVE-2005-0126: ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.
nvd
CVE-2009-2192P4HIGHCVSS 7.5v10.5v10.5.0+7 more2009-08-06
CVE-2009-2192 [HIGH] CWE-255 CVE-2009-2192: MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for attackers to hijack a MobileMe session via unspecified vectors, related to a "logic issue."
nvd
CVE-2015-0253P4MEDIUMCVSS 5.0v5.0.32015-07-20
CVE-2015-0253 [MEDIUM] CVE-2015-0253: The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initia The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400
nvd
CVE-2009-0160P4MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0160 [MEDIUM] CWE-94 CVE-2009-0160: QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execut QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.
nvd
CVE-2010-0062P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0062 [MEDIUM] CWE-119 CVE-2010-0062: Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6 Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.
nvd
CVE-2012-0658P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0658 [MEDIUM] CWE-119 CVE-2012-0658: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbi Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio sample tables in a movie file that is progressively downloaded.
nvd
CVE-2010-3785P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-3785 [MEDIUM] CWE-119 CVE-2010-3785: Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attacke Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document.
nvd
Apple Mac Os X Server vulnerabilities | cvebase