Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 13 of 33
CVE-2011-3223P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3223 [MEDIUM] CWE-119 CVE-2011-3223: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbi
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.
nvd
CVE-2011-3222P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3222 [MEDIUM] CWE-119 CVE-2011-3222: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbi
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
nvd
CVE-2010-3791P4MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3791 [MEDIUM] CWE-119 CVE-2010-3791: Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execu
Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.
nvd
CVE-2010-0513P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0513 [MEDIUM] CWE-119 CVE-2010-0513: Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers
Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PostScript document.
nvd
CVE-2009-2826P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2826 [MEDIUM] CWE-189 CVE-2009-2826: Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execut
Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based buffer overflow.
nvd
CVE-2003-0601P4HIGHCVSS 7.5v10.2v10.2.1+5 more2004-03-29
CVE-2003-0601 [HIGH] CVE-2003-0601: Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.
nvd
CVE-2010-1376P4MEDIUMCVSS 6.8v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1376 [MEDIUM] CWE-134 CVE-2010-1376: Multiple format string vulnerabilities in Network Authorization in Apple Mac OS X 10.6 before 10.6.4
Multiple format string vulnerabilities in Network Authorization in Apple Mac OS X 10.6 before 10.6.4 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) afp, (2) cifs, or (3) smb URL.
nvd
CVE-2012-0659P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0659 [MEDIUM] CWE-189 CVE-2012-0659: Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arb
Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.
nvd
CVE-2011-3213P4HIGHCVSS 7.6≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3213 [HIGH] CWE-264 CVE-2011-3213: The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.50
The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.
nvd
CVE-2009-1717P4MEDIUMCVSS 6.8v10.5v10.5.0+6 more2009-06-05
CVE-2009-1717 [MEDIUM] CWE-189 CVE-2009-1717: Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute
Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.
nvd
CVE-2011-3221P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3221 [MEDIUM] CWE-94 CVE-2011-3221: QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files
QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.
nvd
CVE-2013-1024P4MEDIUMCVSS 6.8v10.7.0v10.7.1+4 more2013-06-05
CVE-2013-1024 [MEDIUM] CWE-20 CVE-2013-1024: CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the pr
CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2010-1845P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-1845 [MEDIUM] CWE-20 CVE-2010-1845: ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitra
ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image.
nvd
CVE-2010-0497P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0497 [MEDIUM] CVE-2010-0497: Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected warning for an unsafe file
Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected warning for an unsafe file type in an internet enabled disk image, which makes it easier for user-assisted remote attackers to execute arbitrary code via a package file type.
nvd
CVE-2011-3450P4MEDIUMCVSS 6.8v10.7.0v10.7.1+1 more2012-02-02
CVE-2011-3450 [MEDIUM] CWE-399 CVE-2011-3450: CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack mem
CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via a long URL.
nvd
CVE-2010-3783P4MEDIUMCVSS 6.8v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-3783 [MEDIUM] CWE-264 CVE-2010-3783: Password Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly perform replicat
Password Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly perform replication, which allows remote authenticated users to bypass verification of the current password via unspecified vectors.
nvd
CVE-2011-0212P4MEDIUMCVSS 6.4v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0212 [MEDIUM] CWE-399 CVE-2011-0212: servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and poss
servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
nvd
CVE-2006-1983P4MEDIUMCVSS 6.4v10.3v10.3.1+15 more2006-04-21
CVE-2006-1983 [MEDIUM] CWE-119 CVE-2006-1983: Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause
Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit. NOTE: the BMP vector has been re-assigned to CVE-200
nvd
CVE-2010-1829P4MEDIUMCVSS 6.0v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1829 [MEDIUM] CWE-22 CVE-2010-1829: Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 al
Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to execute arbitrary code by creating files that are outside the bounds of a share.
nvd
CVE-2004-0823P4HIGHCVSS 7.5v10.2.8v10.3.4+1 more2004-09-07
CVE-2004-0823 [HIGH] CVE-2004-0823: OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.
nvd