cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 27 of 33
CVE-2004-0825P4MEDIUMCVSS 5.0v10.2.8v10.3.4+1 more2004-12-31
CVE-2004-0825 [MEDIUM] CVE-2004-0825: QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to cause a denial of service (application deadlock) via a certain sequence of operations.
nvd
CVE-2006-1457P4LOWCVSS 2.6v10.4.62006-05-12
CVE-2006-1457 [LOW] CVE-2006-1457: Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automat Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.
nvd
CVE-2004-0743P4MEDIUMCVSS 5.0v10.2v10.2.1+12 more2004-11-23
CVE-2004-0743 [MEDIUM] CVE-2004-0743: Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the dat Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward or backward buttons, which may cause an information leak.
nvd
CVE-2008-1036P4MEDIUMCVSS 4.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1036 [MEDIUM] CWE-79 CVE-2008-1036: The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Ente The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2004-0925P4MEDIUMCVSS 5.0v10.3v10.3.1+4 more2005-01-27
CVE-2004-0925 [MEDIUM] CVE-2004-0925: Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the user Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
nvd
CVE-2005-2524P4MEDIUMCVSS 5.0v10.3.92005-10-26
CVE-2005-2524 [MEDIUM] CVE-2005-2524: Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
nvd
CVE-2010-0525P4MEDIUMCVSS 5.0≤ 10.6.2v10.5.0+10 more2010-03-30
CVE-2010-0525 [MEDIUM] CWE-310 CVE-2010-0525: Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during proces Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive information via a brute-force attack on a weakly encrypted e-mail message.
nvd
CVE-2004-0924P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0924 [MEDIUM] CVE-2004-0924: NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root acc NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
nvd
CVE-2004-0927P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0927 [MEDIUM] CVE-2004-0927: ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
nvd
CVE-2008-3622P4MEDIUMCVSS 4.3v10.5v10.5.1+3 more2008-09-16
CVE-2008-3622 [MEDIUM] CWE-79 CVE-2008-3622: Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka "persistent JavaScript injection."
nvd
CVE-2009-0144P4MEDIUMCVSS 4.3v10.5.1v10.5.2+3 more2009-05-13
CVE-2009-0144 [MEDIUM] CWE-16 CVE-2009-0144: CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie heade CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.
nvd
CVE-2011-3447P4MEDIUMCVSS 4.3v10.7.0v10.7.1+1 more2012-02-02
CVE-2011-3447 [MEDIUM] CWE-200 CVE-2011-3447: CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.
nvd
CVE-2010-0064P4MEDIUMCVSS 6.9v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0064 [MEDIUM] CWE-264 CVE-2010-0064: DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticate DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users.
nvd
CVE-2005-2714P4MEDIUMCVSS 6.8v10.3v10.3.1+14 more2005-12-31
CVE-2005-2714 [MEDIUM] CWE-59 CVE-2005-2714: passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] temporary file.
nvd
CVE-2006-1984P4MEDIUMCVSS 5.0≤ 10.4.5v10.3+14 more2006-04-21
CVE-2006-1984 [MEDIUM] CVE-2006-1984: Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used i Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference.
nvd
CVE-2006-3496P4MEDIUMCVSS 5.0v10.3.9v10.4.72006-08-02
CVE-2006-3496 [MEDIUM] CVE-2006-3496: AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (c AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.
nvd
CVE-2005-0127P4MEDIUMCVSS 5.0v10.3.72005-05-02
CVE-2005-0127 [MEDIUM] CVE-2005-0127: Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes inform Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
nvd
CVE-2004-0744P4MEDIUMCVSS 5.0v10.2v10.2.1+12 more2004-11-23
CVE-2004-0744 [MEDIUM] CVE-2004-0744: The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
nvd
CVE-2003-1005P4MEDIUMCVSS 5.0v10.2.8v10.3.22003-12-31
CVE-2003-1005 [MEDIUM] CVE-2003-1005: The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of ser The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
nvd
CVE-2003-0804P4MEDIUMCVSS 5.0v10.2v10.2.1+6 more2003-11-17
CVE-2003-0804 [MEDIUM] CVE-2003-0804: The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-ba The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.
nvd