Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 21 of 33
CVE-2007-0747P4HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0747 [HIGH] CVE-2007-0747: load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mou
load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2007-0744P4HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0744 [HIGH] CVE-2007-0744: SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing c
SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2009-0151P4HIGHCVSS 7.2v10.5v10.5.0+7 more2009-08-06
CVE-2009-0151 [HIGH] CVE-2009-0151: The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Tou
The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors.
nvd
CVE-2008-4218P4HIGHCVSS 7.2≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4218 [HIGH] CWE-189 CVE-2008-4218: Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow lo
Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call to (1) i386_set_ldt or (2) i386_get_ldt.
nvd
CVE-2008-1027P4MEDIUMCVSS 4.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1027 [MEDIUM] CWE-264 CVE-2008-1027: Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested fi
Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic.
nvd
CVE-2009-0011P4HIGHCVSS 7.2v10.5.62009-02-13
CVE-2009-0011 [HIGH] CWE-264 CVE-2009-0011: Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via u
Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file.
nvd
CVE-2009-2196P4MEDIUMCVSS 5.0v10.4.11v10.5.7+1 more2009-08-12
CVE-2009-2196 [MEDIUM] CVE-2009-2196: Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbit
Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
nvd
CVE-2004-0112P4MEDIUMCVSS 5.0v10.3.32004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2008-0046P4MEDIUMCVSS 5.0v10.5.22008-03-18
CVE-2008-0046 [MEDIUM] CWE-264 CVE-2008-0046: The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set a
The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.
nvd
CVE-2006-0398P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0398 [HIGH] CVE-2006-0398: Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 1
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.
nvd
CVE-2006-0399P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0399 [HIGH] CVE-2006-0399: Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 1
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.
nvd
CVE-2006-0397P4HIGHCVSS 7.5v10.4v10.4.1+4 more2006-03-14
CVE-2006-0397 [HIGH] CWE-94 CVE-2006-0397: Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 1
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.
nvd
CVE-2008-4236P4HIGHCVSS 7.1≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4236 [HIGH] CWE-399 CVE-2008-4236: Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a de
Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file.
nvd
CVE-2014-1296P4MEDIUMCVSS 4.3v10.7.0v10.7.1+4 more2014-04-23
CVE-2014-1296 [MEDIUM] CWE-264 CVE-2014-1296: CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not e
CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated b
nvd
CVE-2006-3500P4HIGHCVSS 7.2v10.4.72006-08-03
CVE-2006-3500 [HIGH] CVE-2006-3500: The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via
The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via an "improperly handled condition" that leads to use of "dangerous paths," probably related to an untrusted search path vulnerability.
nvd
CVE-2007-4693P4HIGHCVSS 7.2v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4693 [HIGH] CWE-287 CVE-2007-4693: The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access t
The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between secure text fields."
nvd
CVE-2008-3609P4HIGHCVSS 7.2v10.5v10.5.1+3 more2008-09-16
CVE-2008-3609 [HIGH] CWE-264 CVE-2008-3609: The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during r
The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file.
nvd
CVE-2007-0732P4HIGHCVSS 7.2v10.4v10.4.1+8 more2007-04-24
CVE-2007-0732 [HIGH] CVE-2007-0732: Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10
Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."
nvd
CVE-2010-1802P4MEDIUMCVSS 6.4v10.5.8v10.6.42010-08-25
CVE-2010-1802 [MEDIUM] CWE-287 CVE-2010-1802: libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name
libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.
nvd
CVE-2008-3611P4MEDIUMCVSS 6.3v10.4.112008-09-16
CVE-2008-3611 [MEDIUM] CWE-287 CVE-2008-3611: Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a passw
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
nvd