Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 19 of 33
CVE-2009-2807P4HIGHCVSS 7.2v10.5.82009-09-14
CVE-2009-2807 [HIGH] CWE-119 CVE-2009-2807: Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to
Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-0992P4MEDIUMCVSS 5.8v10.5.22008-03-18
CVE-2008-0992 [MEDIUM] CWE-119 CVE-2008-0992: Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbi
Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value.
nvd
CVE-2007-0897P4HIGHCVSS 7.5fixed in 10.4.112007-02-16
CVE-2007-0897 [HIGH] CWE-772 CVE-2007-0897: Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, whi
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
nvd
CVE-2005-1341P4MEDIUMCVSS 5.1v10.3v10.3.1+8 more2005-05-04
CVE-2005-1341 [MEDIUM] CVE-2005-1341: Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
nvd
CVE-2008-4222P4HIGHCVSS 7.1≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4222 [HIGH] CWE-399 CVE-2008-4222: natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remot
natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinite loop) via a crafted TCP packet.
nvd
CVE-2010-0526P4MEDIUMCVSS 4.3v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0526 [MEDIUM] CWE-119 CVE-2010-0526: Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows
Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPEG encoding, which is not properly handled during decompression.
nvd
CVE-2011-3246P4MEDIUMCVSS 5.0v10.7.0v10.7.12011-10-14
CVE-2011-3246 [MEDIUM] CWE-200 CVE-2011-3246: CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, wh
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.
nvd
CVE-2004-0168P4CRITICALCVSS 10.0v10.2.8v10.3.22004-03-15
CVE-2004-0168 [CRITICAL] CVE-2004-0168: Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."
Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."
nvd
CVE-2007-0722P4MEDIUMCVSS 6.8v10.3.9v10.4+8 more2007-03-13
CVE-2007-0722 [MEDIUM] CVE-2007-0722: Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attack
Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.
nvd
CVE-2016-1787P4MEDIUMCVSS 5.3≤ 5.0.152016-03-24
CVE-2016-1787 [MEDIUM] CWE-200 CVE-2016-1787: Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
nvd
CVE-2004-0090P4CRITICALCVSS 10.0v10.1.5v10.2+11 more2004-12-31
CVE-2004-0090 [CRITICAL] CVE-2004-0090: Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown
Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.
nvd
CVE-2009-2843P4MEDIUMCVSS 5.0v10.5.82009-12-08
CVE-2009-2843 [MEDIUM] CWE-310 CVE-2009-2843: Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for app
Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers to execute arbitrary code via an applet.
nvd
CVE-2015-3165P4MEDIUMCVSS 4.3v5.0.22015-05-28
CVE-2015-3165 [MEDIUM] CVE-2015-3165: Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
nvd
CVE-2007-0725P4HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0725 [HIGH] CVE-2007-0725: Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, whe
Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."
nvd
CVE-2010-0503P4MEDIUMCVSS 6.5≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0503 [MEDIUM] CWE-399 CVE-2010-0503: Use-after-free vulnerability in iChat Server in Apple Mac OS X Server 10.5.8 allows remote authentic
Use-after-free vulnerability in iChat Server in Apple Mac OS X Server 10.5.8 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2005-2744P4MEDIUMCVSS 5.1v10.3v10.3.1+11 more2005-10-25
CVE-2005-2744 [MEDIUM] CVE-2005-2744: Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such
Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file.
nvd
CVE-2008-3643P4HIGHCVSS 7.8v10.5.52008-10-10
CVE-2008-3643 [HIGH] CVE-2008-3643: Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a den
Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a denial of service (continuous termination and restart) via a crafted Desktop file that generates an error when producing its icon, related to an "error recovery issue."
nvd
CVE-2004-1083P4HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-03
CVE-2004-1083 [HIGH] CWE-178 CVE-2004-1083: Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, bu
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
nvd
CVE-2010-0521P4MEDIUMCVSS 5.0≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0521 [MEDIUM] CWE-287 CVE-2010-0521: Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for dir
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.
nvd
CVE-2005-1474P4HIGHCVSS 7.5v10.42005-06-13
CVE-2005-1474 [HIGH] CVE-2005-1474: Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without pro
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
nvd