Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 23 of 33
CVE-2011-0199P4MEDIUMCVSS 5.9≥ 10.6.0, < 10.6.82011-06-24
CVE-2011-0199 [MEDIUM] CWE-295 CVE-2011-0199: The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.
nvd
CVE-2011-0207P4MEDIUMCVSS 5.0v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0207 [MEDIUM] CWE-310 CVE-2011-0207: The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail ap
The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network.
nvd
CVE-2008-3617P4MEDIUMCVSS 5.0v10.5v10.5.1+3 more2008-09-16
CVE-2008-3617 [MEDIUM] CWE-255 CVE-2008-3617: Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a passw
Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input characters beyond the maximum password length, which might make it easier for attackers to guess passwords that the user believed were longer.
nvd
CVE-2013-0990P4MEDIUMCVSS 4.9v10.7.0v10.7.1+4 more2013-06-05
CVE-2013-0990 [MEDIUM] CWE-264 CVE-2013-0990: SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users
SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors.
nvd
CVE-2005-1335P4HIGHCVSS 7.2v10.3.92005-05-04
CVE-2005-1335 [HIGH] CVE-2005-1335: Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chp
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
nvd
CVE-2005-1722P4HIGHCVSS 7.2v10.4v10.4.12005-06-16
CVE-2005-1722 [HIGH] CVE-2005-1722: Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows loca
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.
nvd
CVE-2008-1517P4HIGHCVSS 7.2v10.5v10.5.0+6 more2009-05-13
CVE-2008-1517 [HIGH] CWE-20 CVE-2008-1517: Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users t
Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (system shutdown) via unspecified vectors related to workqueues.
nvd
CVE-2005-0972P4HIGHCVSS 7.2v10.0v10.1+23 more2005-05-12
CVE-2005-0972 [HIGH] CVE-2005-0972: Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to ex
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
nvd
CVE-2007-4686P4HIGHCVSS 7.2v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4686 [HIGH] CWE-189 CVE-2007-4686: Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS
Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5fixed in 10.4.11≥ 10.5.0, < 10.5.8+1 more2009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2012-3723P4MEDIUMCVSS 4.6≤ 10.7.4v10.0+69 more2012-09-20
CVE-2012-3723 [MEDIUM] CWE-119 CVE-2012-3723: Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, w
Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device.
nvd
CVE-2008-0989P4MEDIUMCVSS 6.9v10.5.22008-03-18
CVE-2008-0989 [MEDIUM] CWE-134 CVE-2008-0989: Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to ex
Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to execute arbitrary code via format string specifiers in the local hostname.
nvd
CVE-2006-0392P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-0392 [MEDIUM] CVE-2006-0392: Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service
Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.
nvd
CVE-2005-1331P4MEDIUMCVSS 5.1v10.3v10.3.1+8 more2005-05-04
CVE-2005-1331 [MEDIUM] CVE-2005-1331: The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript:
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.
nvd
CVE-2010-1379P4MEDIUMCVSS 5.0v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1379 [MEDIUM] CWE-20 CVE-2010-1379: Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, w
Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of service (printing failure) by deploying a printing device that has a Unicode character in its printing-service name.
nvd
CVE-2010-1828P4MEDIUMCVSS 5.0v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1828 [MEDIUM] CWE-20 CVE-2010-1828: AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a deni
AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets.
nvd
CVE-2008-0050P4MEDIUMCVSS 5.0v10.4.112008-03-18
CVE-2008-0050 [MEDIUM] CWE-200 CVE-2008-0050: CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via d
CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.
nvd
CVE-2012-0651P4MEDIUMCVSS 5.0v10.6.82012-05-11
CVE-2012-0651 [MEDIUM] CWE-200 CVE-2012-0651: The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain
The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a crafted message.
nvd
CVE-2006-1472P4MEDIUMCVSS 5.0v10.3.92006-08-02
CVE-2006-1472 [MEDIUM] CVE-2006-1472: Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determin
Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the search results.
nvd
CVE-2010-0523P4MEDIUMCVSS 5.0v10.5.82010-03-30
CVE-2010-0523 [MEDIUM] CWE-200 CVE-2010-0523: Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allow
Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java applet.
nvd