cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 16 of 33
CVE-2009-2827P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2827 [MEDIUM] CWE-119 CVE-2009-2827: Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attac Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk image.
nvd
CVE-2009-2811P4MEDIUMCVSS 6.8v10.5.82009-09-14
CVE-2009-2811 [MEDIUM] CWE-94 CVE-2009-2811: Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a .fileloc file, which does not trigger a "potentially unsafe" warning message in the Quarantine feature.
nvd
CVE-2009-2809P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-14
CVE-2009-2809 [MEDIUM] CWE-94 CVE-2009-2809: ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or ca ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PixarFilm encoded TIFF image, related to "multiple memory corruption issues."
nvd
CVE-2008-0045P4HIGHCVSS 7.1v10.4.112008-03-18
CVE-2008-0045 [HIGH] CWE-264 CVE-2008-0045: Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names.
nvd
CVE-2005-1724P4HIGHCVSS 7.5v10.4v10.4.12005-06-08
CVE-2005-1724 [HIGH] CVE-2005-1724: NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a f NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.
nvd
CVE-2009-2805P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-14
CVE-2009-2805 [MEDIUM] CWE-189 CVE-2009-2805: Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to exe Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JBIG2 stream in a PDF file, leading to a heap-based buffer overflow.
nvd
CVE-2011-3458P4MEDIUMCVSS 6.8≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3458 [MEDIUM] CWE-264 CVE-2011-3458: QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 file.
nvd
CVE-2010-0507P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0507 [MEDIUM] CWE-119 CVE-2010-0507: Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbi Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PEF image.
nvd
CVE-2010-0506P4MEDIUMCVSS 6.8v10.5.82010-03-30
CVE-2010-0506 [MEDIUM] CWE-119 CVE-2010-0506: Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary c Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted NEF image.
nvd
CVE-2010-0515P4MEDIUMCVSS 6.8v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0515 [MEDIUM] CWE-119 CVE-2010-0515: QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2009-2800P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-11
CVE-2009-2800 [MEDIUM] CWE-119 CVE-2009-2800: Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute ar Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted alias file.
nvd
CVE-2010-0543P4MEDIUMCVSS 6.8v10.5.8v10.6.0+1 more2010-06-17
CVE-2010-0543 [MEDIUM] CWE-119 CVE-2010-0543: ImageIO in Apple Mac OS X 10.5.8, and 10.6 before 10.6.2, allows remote attackers to execute arbitra ImageIO in Apple Mac OS X 10.5.8, and 10.6 before 10.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with MPEG2 encoding.
nvd
CVE-2011-0194P4MEDIUMCVSS 6.8v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0194 [MEDIUM] CWE-189 CVE-2011-0194: Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.
nvd
CVE-2009-2205P4MEDIUMCVSS 6.8v10.5v10.5.0+7 more2009-09-09
CVE-2009-2205 [MEDIUM] CWE-119 CVE-2009-2205: Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2011-0202P4MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0202 [MEDIUM] CWE-189 CVE-2011-0202: Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.
nvd
CVE-2008-0044P4MEDIUMCVSS 5.8v10.4.11v10.5.22008-03-18
CVE-2008-0044 [MEDIUM] CWE-119 CVE-2008-0044: Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted afp:// URL.
nvd
CVE-2013-0971P4MEDIUMCVSS 6.8v10.6.8v10.7.0+5 more2013-03-15
CVE-2013-0971 [MEDIUM] CWE-399 CVE-2013-0971: Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to ex Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document.
nvd
CVE-2012-0654P4MEDIUMCVSS 6.8≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0654 [MEDIUM] CWE-119 CVE-2012-0654: libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the proce libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.
nvd
CVE-2008-3645P4HIGHCVSS 7.2v10.4.11v10.5.52008-10-10
CVE-2008-3645 [HIGH] CWE-119 CVE-2008-3645: Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Net Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Networking component) in Mac OS X 10.4.11 and 10.5.5 allows local users to execute arbitrary code via unknown vectors.
nvd
CVE-2010-1375P4HIGHCVSS 7.2v10.5.82010-06-17
CVE-2010-1375 [HIGH] CWE-287 CVE-2010-1375: NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authori NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to gain privileges via unspecified vectors.
nvd
Apple Mac Os X Server vulnerabilities | cvebase