Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 2 of 33
CVE-2008-1000P3HIGHCVSS 8.5PoCv10.5.22008-03-18
CVE-2008-1000 [HIGH] CWE-22 CVE-2008-1000: Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (a
Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via ".." sequences in file attachments.
nvd
CVE-2007-6276P3HIGHCVSS 7.8PoCv10.5v10.5.1+2 more2007-12-07
CVE-2007-6276 [HIGH] CWE-189 CVE-2007-6276: The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112.
nvd
CVE-2004-0486P3HIGHCVSS 7.6PoCv10.3v10.3.1+2 more2004-07-07
CVE-2004-0486 [HIGH] CVE-2004-0486: HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.
nvd
CVE-2010-0519P3MEDIUMCVSS 6.8PoCv10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0519 [MEDIUM] CWE-189 CVE-2010-0519: Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arb
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.
nvd
CVE-2013-5704P3MEDIUMCVSS 5.0fixed in 5.0.32014-04-15
CVE-2013-5704 [MEDIUM] CVE-2013-5704: The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHe
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
nvd
CVE-2011-0182P3HIGHCVSS 7.2PoC≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0182 [HIGH] CWE-20 CVE-2011-0182: The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle
The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.
nvd
CVE-2011-3026P3MEDIUMCVSS 6.8≥ 10.7.0, < 10.7.5v10.6.82012-02-16
CVE-2011-3026 [MEDIUM] CWE-190 CVE-2011-3026: Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
nvd
CVE-2006-5051P3HIGHCVSS 8.1fixed in 10.3.9≥ 10.4, ≤ 10.4.82006-09-27
CVE-2006-5051 [HIGH] CWE-415 CVE-2006-5051: Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of ser
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
nvd
CVE-2005-4504P4HIGHCVSS 7.8PoCv10.0v10.1+28 more2005-12-22
CVE-2005-4504 [HIGH] CVE-2005-4504: The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earli
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.
nvd
CVE-2006-3507P4HIGHCVSS 7.2PoCv10.3.9v10.4.72006-09-21
CVE-2006-3507 [HIGH] CVE-2006-3507: Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10
Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.
nvd
CVE-2008-4223P3CRITICALCVSS 10.0≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4223 [CRITICAL] CWE-287 CVE-2008-4223: Podcast Producer in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to bypass authenticati
Podcast Producer in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors.
nvd
CVE-2015-5722P3HIGHCVSS 7.8v5.0.152015-09-05
CVE-2015-5722 [HIGH] CWE-20 CVE-2015-5722: buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attacker
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
nvd
CVE-2009-2422P3CRITICALCVSS 9.8≥ 10.6.0, < 10.6.3v10.5.82009-07-10
CVE-2009-2422 [CRITICAL] CWE-287 CVE-2009-2422: The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rai
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this exa
nvd
CVE-2009-1235P4HIGHCVSS 7.2PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1235 [HIGH] CWE-264 CVE-2009-1235: XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interactio
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
nvd
CVE-2007-0753P4HIGHCVSS 7.2PoCv10.3v10.3.1+18 more2007-05-24
CVE-2007-0753 [HIGH] CWE-134 CVE-2007-0753: Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows loca
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
nvd
CVE-2007-0752P4HIGHCVSS 7.2PoCv10.4.82007-05-24
CVE-2007-0752 [HIGH] CVE-2007-0752: The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to dete
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.
nvd
CVE-2006-0396P4MEDIUMCVSS 5.1PoCv10.4v10.4.1+4 more2006-03-14
CVE-2006-0396 [MEDIUM] CVE-2006-0396: Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-
Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.
nvd
CVE-2006-1985P4MEDIUMCVSS 5.1PoCv10.3v10.3.1+15 more2006-04-21
CVE-2006-1985 [MEDIUM] CWE-119 CVE-2006-1985: Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.
nvd
CVE-2009-0138P3CRITICALCVSS 10.0v10.5.62009-02-13
CVE-2009-0138 [CRITICAL] CWE-287 CVE-2009-0138: servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication crede
servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.
nvd
CVE-2007-0746P3CRITICALCVSS 10.0v10.3.9v10.4+9 more2007-04-24
CVE-2007-0746 [CRITICAL] CVE-2007-0746: Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9
Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".
nvd