cbcvebase.

Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 30 of 33
CVE-2006-0388P4LOWCVSS 2.6v10.3v10.3.1+14 more2006-03-03
CVE-2006-0388 [LOW] CWE-94 CVE-2006-0388: Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect use Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.
nvd
CVE-2011-1132P4MEDIUMCVSS 4.9v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-1132 [MEDIUM] CVE-2011-1132: The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.
nvd
CVE-2010-1847P4MEDIUMCVSS 4.9v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-1847 [MEDIUM] CWE-399 CVE-2010-1847: The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associ The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors.
nvd
CVE-2009-2834P4MEDIUMCVSS 4.9≤ 10.6.1v10.0+57 more2009-11-10
CVE-2009-2834 [MEDIUM] CWE-264 CVE-2009-2834: IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) Bluetooth keyboard via unspecified vectors.
nvd
CVE-2004-1089P4MEDIUMCVSS 4.6v10.2v10.2.1+14 more2004-12-02
CVE-2004-1089 [MEDIUM] CVE-2004-1089: Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.
nvd
CVE-2008-2308P4MEDIUMCVSS 4.6v10.4.1v10.4.2+9 more2008-07-01
CVE-2008-2308 [MEDIUM] CWE-264 CVE-2008-2308: Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms a Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information.
nvd
CVE-2010-0545P4MEDIUMCVSS 4.4v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0545 [MEDIUM] CWE-264 CVE-2010-0545: The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the exp The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an "Apply to enclosed items" action, which allows local users to bypass intended access restrictions via normal filesystem operations.
nvd
CVE-2010-1382P4LOWCVSS 3.5v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-1382 [LOW] CWE-79 CVE-2010-1382: Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10 Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field.
nvd
CVE-2010-3797P4LOWCVSS 3.5v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-3797 [LOW] CWE-79 CVE-2010-3797: Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 1 Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-0015P4MEDIUMCVSS 4.9v10.5.62009-02-13
CVE-2009-0015 [MEDIUM] CWE-255 CVE-2009-0015: Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows loc Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."
nvd
CVE-2005-2510P4MEDIUMCVSS 4.6v10.4v10.4.1+1 more2005-08-19
CVE-2005-2510 [MEDIUM] CVE-2005-2510: The Server Admin tool in servermgr_ipfilter for Mac OS X 10.4 to 10.4.2, when using multiple subnets The Server Admin tool in servermgr_ipfilter for Mac OS X 10.4 to 10.4.2, when using multiple subnets and Address Groups, does not always properly write firewall rules to the Active Rules when certain conditions occur, which could result in firewall policies that are less restrictive than intended by the administrator.
nvd
CVE-2006-0389P4LOWCVSS 2.6v10.4v10.4.1+4 more2006-03-03
CVE-2006-0389 [LOW] CVE-2006-0389: Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.
nvd
CVE-2009-2194P4MEDIUMCVSS 4.9v10.5v10.5.0+7 more2009-08-06
CVE-2009-2194 [MEDIUM] CVE-2009-2194: Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which allows local users to cause a denial of service (system crash) by placing file descriptors in messages sent to a socket that has no receiver, related to a "synchronization issue."
nvd
CVE-2008-4219P4MEDIUMCVSS 4.9≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4219 [MEDIUM] CWE-399 CVE-2008-4219: The kernel in Apple Mac OS X before 10.5.6 allows local users to cause a denial of service (infinite The kernel in Apple Mac OS X before 10.5.6 allows local users to cause a denial of service (infinite loop and system halt) by running an application that is dynamically linked to libraries on an NFS server, related to occurrence of an exception in this application.
nvd
CVE-2008-2312P4MEDIUMCVSS 4.9v10.4.112008-09-16
CVE-2008-2312 [MEDIUM] CWE-255 CVE-2008-2312: Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable file, which allows local users to obtain sensitive information by reading this file.
nvd
CVE-2011-3435P4LOWCVSS 2.1v10.7.0v10.7.12011-10-14
CVE-2011-3435 [LOW] CWE-255 CVE-2011-3435: Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.
nvd
CVE-2003-0518P4MEDIUMCVSS 4.6v10.2v10.2.1+5 more2003-08-18
CVE-2003-0518 [MEDIUM] CVE-2003-0518: The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.
nvd
CVE-2008-0990P4MEDIUMCVSS 4.4v10.4.112008-03-18
CVE-2008-0990 [MEDIUM] CWE-200 CVE-2008-0990: notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications.
nvd
CVE-2010-0546P4LOWCVSS 3.3v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0546 [LOW] CWE-59 CVE-2010-0546: Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitr Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At Startup folder.
nvd
CVE-2003-0913P4MEDIUMCVSS 4.6v10.32003-12-01
CVE-2003-0913 [MEDIUM] CVE-2003-0913: Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "u Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."
nvd
Apple Mac Os X Server vulnerabilities | cvebase