Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 20 of 33
CVE-2007-4697P4MEDIUMCVSS 6.8v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4697 [MEDIUM] CVE-2007-4697: Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers
Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption.
nvd
CVE-2010-0056P4MEDIUMCVSS 6.8v10.5.82010-03-30
CVE-2010-0056 [MEDIUM] CWE-119 CVE-2010-0056: Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remo
Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.
nvd
CVE-2010-1374P4MEDIUMCVSS 4.3v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-1374 [MEDIUM] CWE-22 CVE-2010-1374: Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AI
Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AIM is used, allows remote attackers to create arbitrary files via directory traversal sequences in an inline image-transfer operation.
nvd
CVE-2009-2839P4MEDIUMCVSS 6.8v10.5.82009-11-10
CVE-2009-2839 [MEDIUM] CWE-399 CVE-2009-2839: Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause
Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2007-0729P4HIGHCVSS 7.2v10.0v10.1+25 more2007-04-24
CVE-2007-0729 [HIGH] CWE-264 CVE-2007-0729: Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2007-4269P4HIGHCVSS 7.2v10.4v10.4.0+10 more2007-11-15
CVE-2007-4269 [HIGH] CWE-189 CVE-2007-4269: Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local use
Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow.
nvd
CVE-2007-5860P4HIGHCVSS 7.2v10.5.12007-12-19
CVE-2007-5860 [HIGH] CVE-2007-5860: Unspecified vulnerability in Spin Tracer in Apple Mac OS X 10.5.1 allows local users to execute arbi
Unspecified vulnerability in Spin Tracer in Apple Mac OS X 10.5.1 allows local users to execute arbitrary code via unspecified output files, involving an "insecure file operation."
nvd
CVE-2010-0509P4HIGHCVSS 7.2≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0509 [HIGH] CWE-264 CVE-2010-0509: SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via v
SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership during access to the home directories of user accounts.
nvd
CVE-2007-1863P4MEDIUMCVSS 5.0v10.0v10.1+34 more2007-06-27
CVE-2007-1863 [MEDIUM] CVE-2007-1863: cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a th
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
nvd
CVE-2006-1473P4MEDIUMCVSS 5.0v10.3.9v10.4.72006-08-02
CVE-2006-1473 [MEDIUM] CVE-2006-1473: Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause
Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.
nvd
CVE-2008-0059P4MEDIUMCVSS 5.8v10.4.112008-03-18
CVE-2008-0059 [MEDIUM] CWE-362 CVE-2008-0059: Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
nvd
CVE-2010-0540P4MEDIUMCVSS 6.0v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0540 [MEDIUM] CWE-352 CVE-2010-0540: Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used o
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
nvd
CVE-2004-0167P4HIGHCVSS 7.5v10.2.8v10.3.22004-03-15
CVE-2004-0167 [HIGH] CVE-2004-0167: DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media
DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.
nvd
CVE-2003-0049P4HIGHCVSS 7.5v10.2v10.2.1+2 more2003-03-03
CVE-2003-0049 [HIGH] CVE-2003-0049: Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users b
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
nvd
CVE-2011-3225P4MEDIUMCVSS 5.0v10.7.0v10.7.12011-10-14
CVE-2011-3225 [MEDIUM] CWE-264 CVE-2011-3225: The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users
The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody account.
nvd
CVE-2009-2818P4MEDIUMCVSS 5.0≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2818 [MEDIUM] CWE-264 CVE-2009-2818: Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH
Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force attack (aka dictionary attack).
nvd
CVE-2005-3712P4MEDIUMCVSS 6.5v10.4v10.4.1+4 more2005-12-31
CVE-2005-3712 [MEDIUM] CWE-119 CVE-2005-3712: Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated user
Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated users to execute arbitrary code via long extended attributes.
nvd
CVE-2010-1844P4HIGHCVSS 7.1v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-1844 [HIGH] CWE-20 CVE-2010-1844: Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote atta
Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consumption and system crash) via a crafted image.
nvd
CVE-2008-1573P4HIGHCVSS 7.1≤ 10.5.2v10.4.11+2 more2008-06-02
CVE-2008-1573 [HIGH] CWE-119 CVE-2008-1573: The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attac
The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read.
nvd
CVE-2008-2310P4MEDIUMCVSS 6.8≤ 10.5.3v10.4.1+13 more2008-07-01
CVE-2008-2310 [MEDIUM] CWE-134 CVE-2008-2310: Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted att
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
nvd