Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 24 of 33
CVE-2009-2808P4MEDIUMCVSS 5.4≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2808 [MEDIUM] CWE-310 CVE-2009-2808: Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help
Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-middle attackers to send a crafted help:runscript link, and thereby execute arbitrary code, via a spoofed response.
nvd
CVE-2011-3462P4MEDIUMCVSS 5.0≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3462 [MEDIUM] CVE-2011-3462: Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP
Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a different vulnerability than CVE-2010-1803.
nvd
CVE-2004-0821P4HIGHCVSS 7.2v10.2.8v10.3.4+1 more2004-12-31
CVE-2004-0821 [HIGH] CVE-2004-0821: The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, w
The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.
nvd
CVE-2005-2504P4HIGHCVSS 7.2v10.4.22005-08-19
CVE-2005-2504 [HIGH] CVE-2005-2504: The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No"
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.
nvd
CVE-2005-3701P4HIGHCVSS 7.2v10.3.9v10.4.32005-12-01
CVE-2005-3701 [HIGH] CVE-2005-3701: Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an O
Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users to gain privileges via unknown attack vectors.
nvd
CVE-2008-0055P4HIGHCVSS 7.2v10.4.112008-03-18
CVE-2008-0055 [HIGH] CWE-362 CVE-2008-0055: Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies f
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.
nvd
CVE-2007-0724P4MEDIUMCVSS 6.9v10.4v10.4.1+7 more2007-03-13
CVE-2007-0724 [MEDIUM] CVE-2007-0724: The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit
The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
nvd
CVE-2005-3702P4MEDIUMCVSS 5.0v10.3.9v10.4.32005-12-01
CVE-2005-3702 [MEDIUM] CVE-2005-3702: Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be do
Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be downloaded to locations outside the download directory via a long file name.
nvd
CVE-2009-0153P4MEDIUMCVSS 4.3v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0153 [MEDIUM] CWE-79 CVE-2009-0153: International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote att
nvd
CVE-2011-0183P4MEDIUMCVSS 5.0≤ 10.6.6v10.5.8+6 more2011-03-23
CVE-2011-0183 [MEDIUM] CWE-189 CVE-2011-0183: Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an
Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an "integer truncation issue."
nvd
CVE-2007-4688P4MEDIUMCVSS 5.0v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4688 [MEDIUM] CWE-200 CVE-2007-4688: The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain al
The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addresses, via a Node Information Query.
nvd
CVE-2004-0518P4HIGHCVSS 7.5v10.3v10.3.1+2 more2004-08-18
CVE-2004-0518 [HIGH] CVE-2004-0518: Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporti
Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.
nvd
CVE-2005-3704P4MEDIUMCVSS 5.0v10.4v10.4.1+2 more2005-12-01
CVE-2005-3704 [MEDIUM] CVE-2005-3704: System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof s
System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as newline (NL).
nvd
CVE-2008-2331P4MEDIUMCVSS 5.0v10.5v10.5.1+3 more2008-09-16
CVE-2008-2331 [MEDIUM] CWE-264 CVE-2008-2331: Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Inf
Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.
nvd
CVE-2011-0231P4MEDIUMCVSS 5.0≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-0231 [MEDIUM] CWE-200 CVE-2011-0231: CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy
CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."
nvd
CVE-2008-4224P4HIGHCVSS 7.1≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4224 [HIGH] CWE-20 CVE-2008-4224: UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (sys
UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafted ISO file.
nvd
CVE-2007-4678P4HIGHCVSS 7.1v10.4v10.4.1+9 more2007-11-15
CVE-2007-4678 [HIGH] CVE-2007-4678: AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of se
AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted.
nvd
CVE-2010-0511P4MEDIUMCVSS 5.0v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0511 [MEDIUM] CWE-264 CVE-2010-0511: Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast C
Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast Composer workflow when this workflow is overwritten, which allows attackers to access a workflow via unspecified vectors.
nvd
CVE-2013-0967P4MEDIUMCVSS 4.3v10.7.0v10.7.1+2 more2013-03-15
CVE-2013-0967 [MEDIUM] CVE-2013-0967: CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.
nvd
CVE-2011-3444P4MEDIUMCVSS 4.3≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3444 [MEDIUM] CWE-310 CVE-2011-3444: Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon fai
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
nvd