Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 28 of 33
CVE-2003-0975P4MEDIUMCVSS 5.0v10.2.8v10.3.12003-12-15
CVE-2003-0975 [MEDIUM] CVE-2003-0975: Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal
Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
nvd
CVE-2004-0922P4MEDIUMCVSS 5.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0922 [MEDIUM] CVE-2004-0922: AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest g
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
nvd
CVE-2011-0172P4MEDIUMCVSS 4.9v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0172 [MEDIUM] CVE-2011-0172: AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (d
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.
nvd
CVE-2007-4695P4MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4695 [MEDIUM] CWE-20 CVE-2007-4695: Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allow
Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to modify form field values via unknown vectors related to file uploads.
nvd
CVE-2010-1373P4MEDIUMCVSS 4.3v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1373 [MEDIUM] CWE-79 CVE-2010-1373: Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows
Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted help: URL, related to "URL parameters in HTML content."
nvd
CVE-2006-1471P4MEDIUMCVSS 4.6v10.4v10.4.1+5 more2006-06-27
CVE-2006-1471 [MEDIUM] CWE-134 CVE-2006-1471: Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 al
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.
nvd
CVE-2007-4696P4MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4696 [MEDIUM] CWE-362 CVE-2007-4696: Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain i
Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari.
nvd
CVE-2011-3214P4MEDIUMCVSS 4.6≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3214 [MEDIUM] CWE-264 CVE-2011-3214: IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in displa
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.
nvd
CVE-2010-0534P4MEDIUMCVSS 4.0v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0534 [MEDIUM] CWE-264 CVE-2010-0534: Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (S
Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.
nvd
CVE-2003-0198P4MEDIUMCVSS 6.4v10.0v10.2+4 more2003-05-05
CVE-2003-0198 [MEDIUM] CVE-2003-0198: Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read u
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
nvd
CVE-2010-4011P4MEDIUMCVSS 4.0v10.6.52010-11-17
CVE-2010-4011 [MEDIUM] CWE-200 CVE-2010-4011: Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
nvd
CVE-2006-0383P4MEDIUMCVSS 5.0v10.3v10.3.1+14 more2006-03-02
CVE-2006-0383 [MEDIUM] CVE-2006-0383: IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a
IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".
nvd
CVE-2002-1265P4MEDIUMCVSS 5.0v10.0v10.2+1 more2002-11-12
CVE-2002-1265 [MEDIUM] CVE-2002-1265: The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism whe
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
nvd
CVE-2004-0166P4MEDIUMCVSS 5.0v10.2.82004-03-15
CVE-2004-0166 [MEDIUM] CVE-2004-0166: Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in t
Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."
nvd
CVE-2011-3224P4LOWCVSS 2.6≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3224 [LOW] CVE-2011-3224: The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.
nvd
CVE-2004-0428P4MEDIUMCVSS 5.0v10.2v10.2.1+11 more2004-05-03
CVE-2004-0428 [MEDIUM] CVE-2004-0428: Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "t
Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.
nvd
CVE-2005-2745P4MEDIUMCVSS 5.0v10.3.92005-10-26
CVE-2005-2745 [MEDIUM] CVE-2005-2745: Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can inclu
Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information.
nvd
CVE-2008-2330P4MEDIUMCVSS 4.9v10.4.11v10.5+4 more2008-09-16
CVE-2008-2330 [MEDIUM] CWE-200 CVE-2008-2330: slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select
slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
nvd
CVE-2008-0988P4MEDIUMCVSS 4.3v10.4.112008-03-18
CVE-2008-0988 [MEDIUM] CWE-189 CVE-2008-0988: Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-depen
Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.
nvd
CVE-2005-2742P4MEDIUMCVSS 4.6v10.4.22005-10-26
CVE-2005-2742 [MEDIUM] CVE-2005-2742: SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..."
SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from sleep or screen saver" setting.
nvd