Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 25 of 33
CVE-2011-3444P4MEDIUMCVSS 4.3≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3444 [MEDIUM] CWE-310 CVE-2011-3444: Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon fai
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
nvd
CVE-2014-0067P4MEDIUMCVSS 4.6v5.0.32014-03-31
CVE-2014-0067 [MEDIUM] CWE-264 CVE-2014-0067: The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invok
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
nvd
CVE-2011-3422P4MEDIUMCVSS 4.3≤ 10.6.8v10.6.0+7 more2011-09-12
CVE-2011-3422 [MEDIUM] CWE-20 CVE-2011-3422: The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrust
The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.
nvd
CVE-2012-0649P4MEDIUMCVSS 6.9≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0649 [MEDIUM] CWE-362 CVE-2012-0649: Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 a
Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors involving a temporary file.
nvd
CVE-2005-2502P4MEDIUMCVSS 5.1v10.3.9v10.4.22005-08-19
CVE-2005-2502 [MEDIUM] CVE-2005-2502: Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit,
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.
nvd
CVE-2006-3502P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-3502 [MEDIUM] CVE-2006-3502: Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to caus
Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly handled.
nvd
CVE-2002-0666P4MEDIUMCVSS 5.0v10.22002-11-04
CVE-2002-0666 [MEDIUM] CVE-2002-0666: IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of a
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
nvd
CVE-2004-1084P4MEDIUMCVSS 5.0v10.2v10.2.1+14 more2004-12-02
CVE-2004-1084 [MEDIUM] CVE-2004-1084: Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork
Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
nvd
CVE-2009-0156P4MEDIUMCVSS 4.3v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0156 [MEDIUM] CWE-20 CVE-2009-0156: Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a
Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read.
nvd
CVE-2010-1800P4MEDIUMCVSS 5.0v10.6.3v10.6.42010-08-25
CVE-2010-1800 [MEDIUM] CWE-200 CVE-2010-1800: CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allo
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.
nvd
CVE-2011-0189P4MEDIUMCVSS 5.0v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0189 [MEDIUM] CWE-16 CVE-2011-0189: The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version
The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulnerabilities.
nvd
CVE-2009-2814P4MEDIUMCVSS 4.3v10.5.82009-09-14
CVE-2009-2814 [MEDIUM] CWE-79 CVE-2009-2814: Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple Mac OS X 10.5.8 allows remote a
Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple Mac OS X 10.5.8 allows remote attackers to inject arbitrary web script or HTML via a search request containing data that does not use UTF-8 encoding.
nvd
CVE-2007-0745P4HIGHCVSS 7.1v10.4.92007-05-02
CVE-2007-0745 [HIGH] CVE-2007-0745: The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac O
The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.
nvd
CVE-2009-2823P4MEDIUMCVSS 4.3≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2823 [MEDIUM] CWE-79 CVE-2009-2823: The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows r
The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
nvd
CVE-2011-3452P4MEDIUMCVSS 4.3≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3452 [MEDIUM] CWE-200 CVE-2011-3452: Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across so
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.
nvd
CVE-2009-1723P4MEDIUMCVSS 4.3v10.5v10.5.0+7 more2009-08-06
CVE-2009-1723 [MEDIUM] CVE-2009-1723: CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in c
CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.
nvd
CVE-2011-0190P4MEDIUMCVSS 4.3v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0190 [MEDIUM] CWE-20 CVE-2011-0190: Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified
Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server.
nvd
CVE-2006-3506P4MEDIUMCVSS 4.6v10.4.72006-08-21
CVE-2006-3506 [MEDIUM] CVE-2006-3506: Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local
Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local users with Xsan write access, to execute arbitrary code via unspecified vectors related to "processing a path name."
nvd
CVE-2004-0886P4MEDIUMCVSS 5.0v10.2v10.2.1+14 more2005-01-27
CVE-2004-0886 [MEDIUM] CVE-2004-0886: Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
nvd
CVE-2009-2825P4MEDIUMCVSS 4.3≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2825 [MEDIUM] CVE-2009-2825: Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a
Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408
nvd