Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 15 of 33
CVE-2011-0193P4MEDIUMCVSS 6.8v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0193 [MEDIUM] CWE-119 CVE-2011-0193: Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to exe
Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.
nvd
CVE-2010-0060P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0060 [MEDIUM] CWE-119 CVE-2010-0060: CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause
CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.
nvd
CVE-2011-3448P4MEDIUMCVSS 6.8≤ 10.7.2v10.6.0+10 more2012-02-02
CVE-2011-3448 [MEDIUM] CWE-119 CVE-2011-3448: Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to e
Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2002-1347P4CRITICALCVSS 9.8fixed in 10.3.82002-12-18
CVE-2002-1347 [CRITICAL] CWE-131 CVE-2002-1347: Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not
nvd
CVE-2014-1269P4MEDIUMCVSS 6.8v10.7.0v10.7.1+4 more2014-02-27
CVE-2014-1269 [MEDIUM] CVE-2014-1269: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
nvd
CVE-2014-1270P4MEDIUMCVSS 6.8v10.7.0v10.7.1+4 more2014-02-27
CVE-2014-1270 [MEDIUM] CVE-2014-1270: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
nvd
CVE-2014-1268P4MEDIUMCVSS 6.8v10.7.0v10.7.1+4 more2014-02-27
CVE-2014-1268 [MEDIUM] CWE-119 CVE-2014-1268: WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270.
nvd
CVE-2014-1259P4MEDIUMCVSS 6.8v10.7.0v10.7.1+4 more2014-02-27
CVE-2014-1259 [MEDIUM] CWE-119 CVE-2014-1259: Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary c
Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename.
nvd
CVE-2009-0161P4MEDIUMCVSS 6.4v10.4.11v10.5.0+5 more2009-05-13
CVE-2009-0161 [MEDIUM] CWE-20 CVE-2009-0161: The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified
The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.
nvd
CVE-2009-2801P4MEDIUMCVSS 6.4v10.5.82010-03-30
CVE-2009-2801 [MEDIUM] CWE-264 CVE-2009-2801: The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, w
The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass intended access restrictions via packet data, related to a "timing issue."
nvd
CVE-2009-2813P4MEDIUMCVSS 6.0v10.5.82009-09-14
CVE-2009-2813 [MEDIUM] CWE-264 CVE-2009-2813: Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in t
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictio
nvd
CVE-2010-0535P4MEDIUMCVSS 6.5v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0535 [MEDIUM] CWE-264 CVE-2010-0535: Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce th
Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2008-0058P4MEDIUMCVSS 5.8v10.4.112008-03-18
CVE-2008-0058 [MEDIUM] CWE-362 CVE-2008-0058: Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS
Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.
nvd
CVE-2006-0384P4HIGHCVSS 7.5v10.3v10.3.1+14 more2006-03-02
CVE-2006-0384 [HIGH] CVE-2006-0384: automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (un
automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".
nvd
CVE-2004-0165P4MEDIUMCVSS 5.0v10.1v10.1.1+16 more2004-03-15
CVE-2004-0165 [MEDIUM] CVE-2004-0165: Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2
Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.
nvd
CVE-2008-0063P4HIGHCVSS 7.5fixed in 10.4.11≥ 10.5.0, < 10.5.22008-03-19
CVE-2008-0063 [HIGH] CWE-908 CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
nvd
CVE-2009-2832P4MEDIUMCVSS 5.1≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2832 [MEDIUM] CWE-119 CVE-2009-2832: Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arb
Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a "CWD command line tool."
nvd
CVE-2009-0944P4MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0944 [MEDIUM] CWE-94 CVE-2009-0944: The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.
The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption.
nvd
CVE-2009-0019P4HIGHCVSS 7.5v10.4.11v10.5.62009-02-13
CVE-2009-0019 [HIGH] CWE-119 CVE-2009-0019: Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial o
Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access.
nvd
CVE-2008-0048P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0048 [MEDIUM] CWE-119 CVE-2008-0048: Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers t
Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API.
nvd