cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 3 of 33
CVE-2009-2193P3CRITICALCVSS 10.0v10.5v10.5.0+7 more2009-08-06
CVE-2009-2193 [CRITICAL] CWE-119 CVE-2009-2193: Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execut Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted AppleTalk response packet.
nvd
CVE-2009-0946P3HIGHCVSS 7.5≥ 10.6.0, ≤ 10.6.4v10.4.11+1 more2009-04-17
CVE-2009-0946 [HIGH] CWE-190 CVE-2009-0946: Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
nvd
CVE-2007-0229P4HIGHCVSS 7.2PoCv10.4.82007-01-13
CVE-2007-0229 [HIGH] CVE-2007-0229: Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users t Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does
nvd
CVE-2009-1238P4HIGHCVSS 7.2PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1238 [HIGH] CWE-362 CVE-2009-1238: Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified glo
nvd
CVE-2010-1378P3CRITICALCVSS 9.8≥ 10.6.0, < 10.6.52010-11-15
CVE-2010-1378 [CRITICAL] CWE-295 CVE-2010-1378: OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows re OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.
nvd
CVE-2009-1726P3CRITICALCVSS 9.3v10.4.11v10.5+8 more2009-08-06
CVE-2009-1726 [CRITICAL] CWE-119 CVE-2009-1726: Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remo Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.
nvd
CVE-2010-2941P3CRITICALCVSS 9.8fixed in 10.5.8≥ 10.6.0, ≤ 10.6.42010-11-05
CVE-2010-2941 [CRITICAL] CWE-416 CVE-2010-2941: ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
nvd
CVE-2009-0012P3CRITICALCVSS 10.0v10.5.62009-02-13
CVE-2009-0012 [CRITICAL] CWE-119 CVE-2009-0012: Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute a Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.
nvd
CVE-2003-1006P4HIGHCVSS 7.2PoCv10.0v10.2+11 more2004-03-29
CVE-2003-1006 [HIGH] CVE-2003-1006: Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.
nvd
CVE-2005-0716P4HIGHCVSS 7.2PoCv10.3v10.3.1+5 more2005-03-21
CVE-2005-0716 [HIGH] CVE-2005-0716: Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possib Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.
nvd
CVE-2003-0171P4HIGHCVSS 7.2PoCv10.0v10.2+4 more2003-05-05
CVE-2003-0171 [HIGH] CVE-2003-0171: DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch co DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
nvd
CVE-2009-2820P4MEDIUMCVSS 4.3PoC≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2820 [MEDIUM] CWE-79 CVE-2009-2820: The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configurati
nvd
CVE-2008-3638P3CRITICALCVSS 9.3v10.5.4v10.5.52008-09-26
CVE-2008-3638 [CRITICAL] CWE-94 CVE-2008-3638: Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.
nvd
CVE-2006-3498P3CRITICALCVSS 10.0v10.3.9v10.4.72006-08-02
CVE-2006-3498 [CRITICAL] CVE-2006-3498: Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 all Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request.
nvd
CVE-2008-0599P3CRITICALCVSS 9.8fixed in 10.5.42008-05-05
CVE-2008-0599 [CRITICAL] CWE-131 CVE-2008-0599: The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
nvd
CVE-2006-6062P4MEDIUMCVSS 5.1PoCv10.4.82006-11-22
CVE-2006-6062 [MEDIUM] CVE-2006-6062: Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attac Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.
nvd
CVE-2005-2713P4MEDIUMCVSS 6.8PoCv10.3v10.3.1+14 more2005-12-31
CVE-2005-2713 [MEDIUM] CVE-2005-2713: passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.
nvd
CVE-2007-2401P4MEDIUMCVSS 4.3PoCv10.3.9v10.4.92007-06-25
CVE-2007-2401 [MEDIUM] CWE-79 CVE-2007-2401: CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone befor CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scriptin
nvd
CVE-2008-4217P3CRITICALCVSS 9.3≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4217 [CRITICAL] CWE-189 CVE-2008-4217: Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute a Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO archive, leading to a stack-based buffer overflow.
nvd
CVE-2008-2305P3CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-2305 [CRITICAL] CWE-119 CVE-2008-2305: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 1 Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."
nvd
Apple Mac Os X Server vulnerabilities | cvebase