Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 22 of 33
CVE-2010-1834P4MEDIUMCVSS 5.8v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1834 [MEDIUM] CWE-20 CVE-2010-1834: CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies,
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.
nvd
CVE-2009-2829P4MEDIUMCVSS 5.0v10.5.82009-11-10
CVE-2009-2829 [MEDIUM] CWE-255 CVE-2009-2829: Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to
Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a "log injection" issue.
nvd
CVE-2003-0871P4HIGHCVSS 7.5v10.32003-11-03
CVE-2003-0871 [HIGH] CVE-2003-0871: Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."
nvd
CVE-2005-1339P4HIGHCVSS 7.5v10.3.92005-05-04
CVE-2005-1339 [HIGH] CVE-2005-1339: lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by l
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
nvd
CVE-2005-1723P4HIGHCVSS 7.5v10.4v10.4.12005-06-08
CVE-2005-1723 [HIGH] CVE-2005-1723: LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME
LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsafe types, which could allow attackers to bypass intended restrictions.
nvd
CVE-2004-0921P4HIGHCVSS 7.5v10.2v10.2.1+13 more2005-01-27
CVE-2004-0921 [HIGH] CVE-2004-0921: AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
nvd
CVE-2004-0081P4MEDIUMCVSS 5.0v10.3.32004-11-23
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote atta
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
nvd
CVE-2010-1830P4MEDIUMCVSS 5.0v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1830 [MEDIUM] CVE-2010-1830: AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depe
AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depending on whether a share exists, which allows remote attackers to enumerate valid share names via unspecified vectors.
nvd
CVE-2005-1343P4HIGHCVSS 7.2v10.3.92005-05-03
CVE-2005-1343 [HIGH] CVE-2005-1343: Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users t
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
nvd
CVE-2005-0594P4HIGHCVSS 7.2v10.3.92005-05-04
CVE-2005-0594 [HIGH] CVE-2005-0594: Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
nvd
CVE-2004-0822P4HIGHCVSS 7.2v10.2.8v10.3.4+1 more2004-09-07
CVE-2004-0822 [HIGH] CVE-2004-0822: Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3
Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbitrary code via a certain environment variable.
nvd
CVE-2006-3509P4HIGHCVSS 7.2v10.4.72006-09-21
CVE-2006-3509 [HIGH] CVE-2006-3509: Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow phy
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted frames.
nvd
CVE-2007-1661P4MEDIUMCVSS 6.4v10.4.112007-11-07
CVE-2007-1661 [MEDIUM] CVE-2007-1661: Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certai
Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.
nvd
CVE-2005-0125P4HIGHCVSS 7.2v10.3.72005-05-02
CVE-2005-0125 [HIGH] CVE-2005-0125: The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.
nvd
CVE-2007-4685P4HIGHCVSS 7.2v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4685 [HIGH] CWE-264 CVE-2007-4685: The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing
The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, stderr, or stdout file descriptors are "in an unexpected state."
nvd
CVE-2005-2741P4HIGHCVSS 7.2v10.3.9v10.4.22005-10-26
CVE-2005-2741 [HIGH] CWE-264 CVE-2005-2741: Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges
Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators.
nvd
CVE-2010-1838P4MEDIUMCVSS 4.4v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1838 [MEDIUM] CWE-287 CVE-2010-1838: Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors
Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.
nvd
CVE-2008-0998P4MEDIUMCVSS 6.9v10.4.11v10.5.22008-03-18
CVE-2008-0998 [MEDIUM] CWE-264 CVE-2008-0998: Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4
Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4.11 and 10.5.2 allows local users to bypass authorization and execute arbitrary code via crafted distributed objects.
nvd
CVE-2008-0051P4MEDIUMCVSS 6.9v10.4.112008-03-18
CVE-2008-0051 [MEDIUM] CWE-189 CVE-2008-0051: Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbi
Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.
nvd
CVE-2007-0726P4MEDIUMCVSS 5.0v10.3.9v10.4+8 more2007-03-13
CVE-2007-0726 [MEDIUM] CVE-2007-0726: The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows re
The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.
nvd