cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 29 of 33
CVE-2014-1265P4MEDIUMCVSS 4.6v10.7.0v10.7.1+4 more2014-02-27
CVE-2014-1265 [MEDIUM] CWE-264 CVE-2014-1265: The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local user The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local users to bypass intended access restrictions by changing the current time on the system clock.
nvd
CVE-2009-2835P4MEDIUMCVSS 4.6≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2835 [MEDIUM] CWE-20 CVE-2009-2835: The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allow The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors.
nvd
CVE-2006-0393P4MEDIUMCVSS 4.0v10.4.72006-08-03
CVE-2006-0393 [MEDIUM] CVE-2006-0393: OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine a OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang.
nvd
CVE-2008-4214P4MEDIUMCVSS 4.6v10.4.11v10.5.52008-10-10
CVE-2008-4214 [MEDIUM] CWE-264 CVE-2008-4214: Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to caus Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an "insecure file operation" on temporary files.
nvd
CVE-2009-0150P4MEDIUMCVSS 4.4v10.5.0v10.5.1+5 more2009-05-13
CVE-2009-0150 [MEDIUM] CWE-119 CVE-2009-0150: Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileg Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image.
nvd
CVE-2008-2314P4MEDIUMCVSS 4.4v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2314 [MEDIUM] CWE-264 CVE-2008-2314: Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically pro Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.
nvd
CVE-2005-2746P4MEDIUMCVSS 5.0v10.3.9v10.4.22005-10-26
CVE-2005-2746 [MEDIUM] CVE-2005-2746: Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-repl Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-reply rules, which could cause Mail.app to include decrypted message contents for encrypted messages.
nvd
CVE-2003-1007P4MEDIUMCVSS 5.0v10.2.8v10.3.22004-03-29
CVE-2003-1007 [MEDIUM] CVE-2003-1007: AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.
nvd
CVE-2005-2506P4MEDIUMCVSS 5.0v10.3.9v10.4.22005-08-19
CVE-2005-2506 [MEDIUM] CVE-2005-2506: Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attacker Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.
nvd
CVE-2004-1123P4MEDIUMCVSS 5.0v10.2v10.2.1+14 more2005-01-10
CVE-2004-1123 [MEDIUM] CVE-2004-1123: Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a den Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
nvd
CVE-2006-6353P4MEDIUMCVSS 5.0v10.4.82006-12-07
CVE-2006-6353 [MEDIUM] CVE-2006-6353: Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote atta Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the "iSec Partners FileP fuzzer".
nvd
CVE-2005-3700P4MEDIUMCVSS 4.6v10.3.9v10.4.32005-12-01
CVE-2005-3700 [MEDIUM] CVE-2005-3700: Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Serve Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown attack vectors.
nvd
CVE-2008-1572P4MEDIUMCVSS 4.6v10.4.112008-06-02
CVE-2008-1572 [MEDIUM] CWE-264 CVE-2008-1572: Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows loca Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows local users to overwrite arbitrary files, and display images that are being resized by this application.
nvd
CVE-2006-0401P4MEDIUMCVSS 4.6v10.4.52006-04-05
CVE-2006-0401 [MEDIUM] CVE-2006-0401: Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in Single User Mode via unspecified vectors.
nvd
CVE-2011-0260P4MEDIUMCVSS 4.6v10.7.0v10.7.12011-10-14
CVE-2011-0260 [MEDIUM] CWE-264 CVE-2011-0260: The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window fr The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window.
nvd
CVE-2008-2324P4MEDIUMCVSS 4.6v10.4.112008-08-04
CVE-2008-2324 [MEDIUM] CWE-264 CVE-2008-2324: The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the ema The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.
nvd
CVE-2008-2313P4MEDIUMCVSS 4.6v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2313 [MEDIUM] CWE-264 CVE-2008-2313: Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
nvd
CVE-2009-0149P4MEDIUMCVSS 4.4v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0149 [MEDIUM] CWE-94 CVE-2009-0149: Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denia Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.
nvd
CVE-2007-0728P4MEDIUMCVSS 4.4v10.3.9v10.4+8 more2007-03-13
CVE-2007-0728 [MEDIUM] CVE-2007-0728: Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.
nvd
CVE-2011-0185P4MEDIUMCVSS 4.4≤ 10.7.1v10.7.0+9 more2011-10-14
CVE-2011-0185 [MEDIUM] CWE-134 CVE-2011-0185: Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X b Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.
nvd
Apple Mac Os X Server vulnerabilities | cvebase