Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 31 of 33
CVE-2005-2739P4LOWCVSS 2.1v10.0v10.1+27 more2005-11-01
CVE-2005-2739 [LOW] CVE-2005-2739: Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out
Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out while the password is being viewed, which could allow attackers with physical access to obtain the password.
nvd
CVE-2008-0049P4LOWCVSS 1.9v10.4.112008-03-18
CVE-2008-0049 [LOW] CWE-264 CVE-2008-0049: AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-
AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.
nvd
CVE-2006-5681P4LOWCVSS 2.6v10.4v10.4.1+7 more2006-12-20
CVE-2006-5681 [LOW] CVE-2006-5681: QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote at
QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered by other embedded QuickTime objects.
nvd
CVE-2010-0537P4LOWCVSS 2.6v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0537 [LOW] CWE-264 CVE-2010-0537: DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain
DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a crafted share name.
nvd
CVE-2005-2503P4MEDIUMCVSS 4.6v10.3.9v10.4.22005-08-19
CVE-2005-2503 [MEDIUM] CVE-2005-2503: AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts
AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
nvd
CVE-2003-0420P4MEDIUMCVSS 4.6v10.2.62003-06-13
CVE-2003-0420 [MEDIUM] CVE-2003-0420: Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obta
Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.
nvd
CVE-2004-0517P4MEDIUMCVSS 4.6v10.3v10.3.1+2 more2004-08-18
CVE-2004-0517 [MEDIUM] CVE-2004-0517: Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package install
Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.
nvd
CVE-2004-0515P4MEDIUMCVSS 4.6v10.3v10.3.1+2 more2004-08-18
CVE-2004-0515 [MEDIUM] CVE-2004-0515: Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files.
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."
nvd
CVE-2004-0516P4MEDIUMCVSS 4.6v10.3v10.3.1+2 more2004-08-18
CVE-2004-0516 [MEDIUM] CVE-2004-0516: Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vul
Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.
nvd
CVE-2003-1008P4MEDIUMCVSS 4.6v10.2.8v10.3.22004-03-29
CVE-2003-1008 [MEDIUM] CVE-2003-1008: Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver lo
Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.
nvd
CVE-2012-0657P4LOWCVSS 2.1≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0657 [LOW] CWE-264 CVE-2012-0657: Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, all
Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.
nvd
CVE-2011-3215P4LOWCVSS 2.1≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3215 [LOW] CWE-264 CVE-2011-3215: The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of
The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allows physically proximate attackers to bypass intended access restrictions and discover a password by making a DMA request in the (1) loginwindow, (2) boot, or (3) shutdown state.
nvd
CVE-2013-0982P4LOWCVSS 1.7v10.7.0v10.7.1+4 more2013-06-05
CVE-2013-0982 [LOW] CWE-200 CVE-2013-0982: The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage o
The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.
nvd
CVE-2011-3218P4LOWCVSS 2.6≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-3218 [LOW] CWE-79 CVE-2011-3218: The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML docum
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
nvd
CVE-2008-0994P4LOWCVSS 2.6v10.5.22008-03-18
CVE-2008-0994 [LOW] CWE-200 CVE-2008-0994: Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes
Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.
nvd
CVE-2005-1330P4MEDIUMCVSS 4.9v10.3.92005-05-04
CVE-2005-1330 [MEDIUM] CWE-20 CVE-2005-1330: AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) vi
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
nvd
CVE-2005-0975P4LOWCVSS 2.1v10.3v10.3.1+6 more2005-05-02
CVE-2005-0975 [LOW] CVE-2005-0975: Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the
Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of service (CPU consumption) via a crafted mach-o header.
nvd
CVE-2005-2752P4LOWCVSS 2.1≤ 10.4.22005-11-01
CVE-2005-2752 [LOW] CVE-2005-2752: An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before
An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability than CVE-2005-1126 and CVE-2005-1406.
nvd
CVE-2005-2748P4LOWCVSS 2.1v10.3.9v10.4.22005-10-25
CVE-2005-2748 [LOW] CVE-2005-2748: The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application.
nvd
CVE-2005-1430P4LOWCVSS 3.6v10.0v10.1+24 more2005-05-03
CVE-2005-1430 [LOW] CVE-2005-1430: Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is manage
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
nvd