Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 18 of 33
CVE-2010-0498P4HIGHCVSS 7.2≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0498 [HIGH] CWE-287 CVE-2010-0498: Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during pr
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2010-0058P4MEDIUMCVSS 6.4v10.5.82010-03-30
CVE-2010-0058 [MEDIUM] CWE-16 CVE-2010-0058: freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.
freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.plist ProgramArguments key and consequently does not run, which might allow remote attackers to introduce viruses into the system.
nvd
CVE-2012-0655P4MEDIUMCVSS 6.4≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0655 [MEDIUM] CWE-310 CVE-2012-0655: libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within
libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by conducting a spoofing or network-sniffing attack during communication with a site that uses a short key.
nvd
CVE-2008-1571P4MEDIUMCVSS 5.0v10.4.112008-06-02
CVE-2008-1571 [MEDIUM] CWE-22 CVE-2008-1571: Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X befo
Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
nvd
CVE-2009-2836P4MEDIUMCVSS 6.2v10.6v10.6.12009-11-10
CVE-2009-2836 [MEDIUM] CWE-362 CVE-2009-2836: Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors.
nvd
CVE-2009-2831P4MEDIUMCVSS 5.8v10.5.82009-11-10
CVE-2009-2831 [MEDIUM] CVE-2009-2831: Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any conte
Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any contents, and thereby execute arbitrary code, via crafted JavaScript, related to a "design issue."
nvd
CVE-2016-1774P4MEDIUMCVSS 5.3≤ 5.0.152016-03-24
CVE-2016-1774 [MEDIUM] CWE-284 CVE-2016-1774: The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.
nvd
CVE-2005-1332P4HIGHCVSS 7.5v10.3.92005-05-04
CVE-2005-1332 [HIGH] CVE-2005-1332: Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default,
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
nvd
CVE-2011-0203P4MEDIUMCVSS 5.0v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0203 [MEDIUM] CWE-22 CVE-2011-0203: Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before
Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.
nvd
CVE-2004-0538P4HIGHCVSS 7.5v10.2.8v10.3.42004-08-06
CVE-2004-0538 [HIGH] CVE-2004-0538: LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications,
LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.
nvd
CVE-2015-7031P4MEDIUMCVSS 5.0≤ 5.0.142015-10-23
CVE-2015-7031 [MEDIUM] CWE-264 CVE-2015-7031: The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header config
The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.
nvd
CVE-2007-0721P4MEDIUMCVSS 6.8v10.3.9v10.4+8 more2007-03-13
CVE-2007-0721 [MEDIUM] CVE-2007-0721: Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allo
Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.
nvd
CVE-2009-1727P4MEDIUMCVSS 6.8v10.5v10.5.0+7 more2009-08-06
CVE-2009-1727 [MEDIUM] CVE-2009-1727: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.
nvd
CVE-2009-0009P4MEDIUMCVSS 6.8v10.4.11v10.5.62009-02-13
CVE-2009-0009 [MEDIUM] CWE-119 CVE-2009-0009: Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote att
Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted movie file that triggers memory corruption.
nvd
CVE-2010-0065P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0065 [MEDIUM] CWE-119 CVE-2010-0065: Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitra
Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image with bzip2 compression.
nvd
CVE-2009-2803P4MEDIUMCVSS 6.8v10.4.11v10.5.82009-09-14
CVE-2009-2803 [MEDIUM] CWE-399 CVE-2009-2803: CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause
CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a file with a crafted resource fork.
nvd
CVE-2008-0052P4MEDIUMCVSS 6.8v10.4.112008-03-18
CVE-2008-0052 [MEDIUM] CWE-200 CVE-2008-0052: CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attacker
CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.
nvd
CVE-2011-3227P4MEDIUMCVSS 6.8≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3227 [MEDIUM] CWE-20 CVE-2011-3227: libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a n
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
nvd
CVE-2010-0063P4MEDIUMCVSS 6.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0063 [MEDIUM] CVE-2010-0063: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url e
nvd
CVE-2012-0675P4MEDIUMCVSS 4.3≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0675 [MEDIUM] CWE-287 CVE-2012-0675: Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authenticat
Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.
nvd