Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 23 of 33
CVE-2007-2401MEDIUMCVSS 4.3PoCv10.3.9v10.4.92007-06-25
CVE-2007-2401 [MEDIUM] CWE-79 CVE-2007-2401: CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone befor
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scriptin
nvd
CVE-2007-0750CRITICALCVSS 9.3v10.4v10.4.1+8 more2007-05-24
CVE-2007-0750 [CRITICAL] CVE-2007-0750: Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted att
Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.
nvd
CVE-2007-0753HIGHCVSS 7.2PoCv10.3v10.3.1+18 more2007-05-24
CVE-2007-0753 [HIGH] CWE-134 CVE-2007-0753: Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows loca
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
nvd
CVE-2007-0752HIGHCVSS 7.2PoCv10.4.82007-05-24
CVE-2007-0752 [HIGH] CVE-2007-0752: The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to dete
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.
nvd
CVE-2007-0751LOWCVSS 2.1v10.3v10.3.1+18 more2007-05-24
CVE-2007-0751 [LOW] CVE-2007-0751: A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.
nvd
CVE-2007-0745HIGHCVSS 7.1v10.4.92007-05-02
CVE-2007-0745 [HIGH] CVE-2007-0745: The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac O
The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.
nvd
CVE-2007-0746CRITICALCVSS 10.0v10.3.9v10.4+9 more2007-04-24
CVE-2007-0746 [CRITICAL] CVE-2007-0746: Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9
Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".
nvd
CVE-2007-0735CRITICALCVSS 9.3v10.3.9v10.4+9 more2007-04-24
CVE-2007-0735 [CRITICAL] CVE-2007-0735: Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attack
Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger certain error conditions that are not properly reported in certain circumstances, resulting in accessing d
nvd
CVE-2007-0736CRITICALCVSS 9.3v10.3.9v10.4+9 more2007-04-24
CVE-2007-0736 [CRITICAL] CVE-2007-0736: Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote
Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.
nvd
CVE-2007-0732HIGHCVSS 7.2v10.4v10.4.1+8 more2007-04-24
CVE-2007-0732 [HIGH] CVE-2007-0732: Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10
Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."
nvd
CVE-2007-0747HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0747 [HIGH] CVE-2007-0747: load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mou
load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2007-0725HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0725 [HIGH] CVE-2007-0725: Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, whe
Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."
nvd
CVE-2007-0729HIGHCVSS 7.2v10.0v10.1+25 more2007-04-24
CVE-2007-0729 [HIGH] CWE-264 CVE-2007-0729: Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2007-0744HIGHCVSS 7.2v10.3.9v10.4+9 more2007-04-24
CVE-2007-0744 [HIGH] CVE-2007-0744: SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing c
SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.
nvd
CVE-2007-0731CRITICALCVSS 9.3v10.4v10.4.1+7 more2007-03-13
CVE-2007-0731 [CRITICAL] CVE-2007-0731: Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 1
Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.
nvd
CVE-2007-0723HIGHCVSS 8.5v10.3.9v10.4+8 more2007-03-13
CVE-2007-0723 [HIGH] CVE-2007-0723: Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple
Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors.
nvd
CVE-2007-0719MEDIUMCVSS 6.8v10.3.9v10.4+8 more2007-03-13
CVE-2007-0719 [MEDIUM] CVE-2007-0719: Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assi
Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.
nvd
CVE-2007-0728MEDIUMCVSS 4.4v10.3.9v10.4+8 more2007-03-13
CVE-2007-0728 [MEDIUM] CVE-2007-0728: Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely
Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.
nvd
CVE-2007-0724MEDIUMCVSS 6.9v10.4v10.4.1+7 more2007-03-13
CVE-2007-0724 [MEDIUM] CVE-2007-0724: The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit
The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
nvd
CVE-2007-0726MEDIUMCVSS 5.0v10.3.9v10.4+8 more2007-03-13
CVE-2007-0726 [MEDIUM] CVE-2007-0726: The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows re
The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.
nvd