Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 27 of 33
CVE-2004-0825P4MEDIUMCVSS 5.0v10.2.8v10.3.4+1 more2004-12-31
CVE-2004-0825 [MEDIUM] CVE-2004-0825: QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to
QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to cause a denial of service (application deadlock) via a certain sequence of operations.
nvd
CVE-2006-1457P4LOWCVSS 2.6v10.4.62006-05-12
CVE-2006-1457 [LOW] CVE-2006-1457: Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automat
Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.
nvd
CVE-2004-0743P4MEDIUMCVSS 5.0v10.2v10.2.1+12 more2004-11-23
CVE-2004-0743 [MEDIUM] CVE-2004-0743: Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the dat
Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward or backward buttons, which may cause an information leak.
nvd
CVE-2008-1036P4MEDIUMCVSS 4.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1036 [MEDIUM] CWE-79 CVE-2008-1036: The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Ente
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2004-0925P4MEDIUMCVSS 5.0v10.3v10.3.1+4 more2005-01-27
CVE-2004-0925 [MEDIUM] CVE-2004-0925: Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the user
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
nvd
CVE-2005-2524P4MEDIUMCVSS 5.0v10.3.92005-10-26
CVE-2005-2524 [MEDIUM] CVE-2005-2524: Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
nvd
CVE-2010-0525P4MEDIUMCVSS 5.0≤ 10.6.2v10.5.0+10 more2010-03-30
CVE-2010-0525 [MEDIUM] CWE-310 CVE-2010-0525: Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during proces
Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive information via a brute-force attack on a weakly encrypted e-mail message.
nvd
CVE-2004-0924P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0924 [MEDIUM] CVE-2004-0924: NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root acc
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
nvd
CVE-2004-0927P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0927 [MEDIUM] CVE-2004-0927: ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
nvd
CVE-2008-3622P4MEDIUMCVSS 4.3v10.5v10.5.1+3 more2008-09-16
CVE-2008-3622 [MEDIUM] CWE-79 CVE-2008-3622: Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka "persistent JavaScript injection."
nvd
CVE-2009-0144P4MEDIUMCVSS 4.3v10.5.1v10.5.2+3 more2009-05-13
CVE-2009-0144 [MEDIUM] CWE-16 CVE-2009-0144: CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie heade
CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.
nvd
CVE-2011-3447P4MEDIUMCVSS 4.3v10.7.0v10.7.1+1 more2012-02-02
CVE-2011-3447 [MEDIUM] CWE-200 CVE-2011-3447: CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during
CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.
nvd
CVE-2010-0064P4MEDIUMCVSS 6.9v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0064 [MEDIUM] CWE-264 CVE-2010-0064: DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticate
DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users.
nvd
CVE-2005-2714P4MEDIUMCVSS 6.8v10.3v10.3.1+14 more2005-12-31
CVE-2005-2714 [MEDIUM] CWE-59 CVE-2005-2714: passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] temporary file.
nvd
CVE-2006-1984P4MEDIUMCVSS 5.0≤ 10.4.5v10.3+14 more2006-04-21
CVE-2006-1984 [MEDIUM] CVE-2006-1984: Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used i
Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference.
nvd
CVE-2006-3496P4MEDIUMCVSS 5.0v10.3.9v10.4.72006-08-02
CVE-2006-3496 [MEDIUM] CVE-2006-3496: AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (c
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.
nvd
CVE-2005-0127P4MEDIUMCVSS 5.0v10.3.72005-05-02
CVE-2005-0127 [MEDIUM] CVE-2005-0127: Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes inform
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
nvd
CVE-2004-0744P4MEDIUMCVSS 5.0v10.2v10.2.1+12 more2004-11-23
CVE-2004-0744 [MEDIUM] CVE-2004-0744: The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial
The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
nvd
CVE-2003-1005P4MEDIUMCVSS 5.0v10.2.8v10.3.22003-12-31
CVE-2003-1005 [MEDIUM] CVE-2003-1005: The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of ser
The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
nvd
CVE-2003-0804P4MEDIUMCVSS 5.0v10.2v10.2.1+6 more2003-11-17
CVE-2003-0804 [MEDIUM] CVE-2003-0804: The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-ba
The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.
nvd