Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 17 of 33
CVE-2013-0973P4MEDIUMCVSS 6.8v10.6.8v10.7.0+5 more2013-03-15
CVE-2013-0973 [MEDIUM] CVE-2013-0973: Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketin
Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketing-text WebView, which allows man-in-the-middle attackers to execute plugin code by modifying the client-server data stream.
nvd
CVE-2006-1455P4HIGHCVSS 7.8v10.3.9v10.4.62006-05-12
CVE-2006-1455 [HIGH] CVE-2006-1455: QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a de
QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.
nvd
CVE-2005-2501P4HIGHCVSS 7.6v10.3.9v10.4.22005-08-19
CVE-2005-2501 [HIGH] CVE-2005-2501: Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
nvd
CVE-2006-3505P4HIGHCVSS 7.5v10.3.9v10.4.72006-08-03
CVE-2006-3505 [HIGH] CVE-2006-3505: WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (cra
WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated.
nvd
CVE-2004-1086P4HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-02
CVE-2004-1086 [HIGH] CVE-2004-1086: Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitra
Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.
nvd
CVE-2016-1776P4MEDIUMCVSS 5.3≤ 5.0.152016-03-24
CVE-2016-1776 [MEDIUM] CWE-284 CVE-2016-1776: Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htacc
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.
nvd
CVE-2008-0997P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0997 [MEDIUM] CWE-119 CVE-2008-0997: Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attacker
Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted PostScript Printer Description (PPD) file that is not properly handled when querying a network printer.
nvd
CVE-2006-0400P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0400 [HIGH] CVE-2006-0400: CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin poli
CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."
nvd
CVE-2009-2830P4MEDIUMCVSS 6.8v10.6v10.6.12009-11-10
CVE-2009-2830 [MEDIUM] CVE-2009-2830: Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2
Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.
nvd
CVE-2005-1337P4HIGHCVSS 7.5v10.3.92005-05-04
CVE-2005-1337 [HIGH] CVE-2005-1337: Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arb
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
nvd
CVE-2009-0157P4MEDIUMCVSS 6.8v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0157 [MEDIUM] CWE-119 CVE-2009-0157: Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web serve
Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.
nvd
CVE-2005-3706P4MEDIUMCVSS 6.4v10.4v10.4.1+4 more2005-12-31
CVE-2005-3706 [MEDIUM] CVE-2005-3706: Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent att
Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an application that uses LibSystem to request a large amount of memory.
nvd
CVE-2008-2309P4MEDIUMCVSS 6.8v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2309 [MEDIUM] CWE-264 CVE-2008-2309: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
nvd
CVE-2011-3449P4MEDIUMCVSS 6.8≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3449 [MEDIUM] CWE-399 CVE-2011-3449: Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to
Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
nvd
CVE-2010-4013P4MEDIUMCVSS 6.8v10.6.0v10.6.1+4 more2011-01-10
CVE-2010-4013 [MEDIUM] CWE-134 CVE-2010-4013: Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-m
Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to interaction between Software Update and distribution scripts.
nvd
CVE-2008-0060P4MEDIUMCVSS 6.8v10.4.11v10.5.22008-03-18
CVE-2008-0060 [MEDIUM] CWE-94 CVE-2008-0060: Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Apples
Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.
nvd
CVE-2011-0173P4MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0173 [MEDIUM] CWE-134 CVE-2011-0173: Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.
nvd
CVE-2006-3508P4HIGHCVSS 7.2v10.4.72006-09-21
CVE-2006-3508 [HIGH] CVE-2006-3508: Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates.
nvd
CVE-2009-0017P4HIGHCVSS 7.2v10.4.11v10.5.62009-02-13
CVE-2009-0017 [HIGH] CWE-119 CVE-2009-0017: csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle
csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.
nvd
CVE-2011-3463P4HIGHCVSS 7.2v10.7.0v10.7.1+1 more2012-02-02
CVE-2011-3463 [HIGH] CWE-287 CVE-2011-3463: WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, whic
WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server or (2) a bound directory.
nvd