Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 32 of 33
CVE-2008-0995P4LOWCVSS 2.6v10.5.22008-03-18
CVE-2008-0995 [LOW] CWE-200 CVE-2008-0995: The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF fi
The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods.
nvd
CVE-2006-3495P4LOWCVSS 2.1v10.3.9v10.4.72006-08-02
CVE-2006-3495 [LOW] CVE-2006-3495: AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users.
nvd
CVE-2005-3782P4LOWCVSS 2.1v10.4.3v10.4.4+2 more2005-12-31
CVE-2005-3782 [LOW] CVE-2005-3782: Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show t
Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to bypass login and reboot the system by entering ">restart", ">power", or ">shutdown" sequences after the username.
nvd
CVE-2006-1981P4LOWCVSS 2.1v10.4.52006-04-21
CVE-2006-1981 [LOW] CVE-2006-1981: Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send inp
Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen.
nvd
CVE-2005-2751P4LOWCVSS 2.1v10.4v10.4.1+1 more2005-11-01
CVE-2005-2751 [LOW] CVE-2005-2751: memberd in Mac OS X 10.4 up to 10.4.2, in certain situations, does not quickly synchronize access co
memberd in Mac OS X 10.4 up to 10.4.2, in certain situations, does not quickly synchronize access control checks with changes in group membership, which could allow users to access files and other resources after they have been removed from a group.
nvd
CVE-2003-0876P4LOWCVSS 2.1v10.0v10.2+8 more2003-11-03
CVE-2003-0876 [LOW] CVE-2003-0876: Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.
nvd
CVE-2012-3718P4LOWCVSS 2.1≤ 10.7.4v10.0+69 more2012-09-20
CVE-2012-3718 [LOW] CWE-200 CVE-2012-3718: Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered i
Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.
nvd
CVE-2008-2329P4LOWCVSS 1.9v10.5v10.5.1+3 more2008-09-16
CVE-2008-2329 [LOW] CWE-200 CVE-2008-2329: Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows atta
Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows attackers to enumerate user names via wildcard characters in the Login Window.
nvd
CVE-2005-1727P4LOWCVSS 3.7v10.4v10.4.12005-06-08
CVE-2005-1727 [LOW] CVE-2005-1727: Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) s
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."
nvd
CVE-2006-3356P4LOWCVSS 2.6≤ 10.4.72006-07-06
CVE-2006-3356 [LOW] CVE-2006-3356: The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assist
The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue than CVE-2006-1469.
nvd
CVE-2006-6127P4LOWCVSS 2.1v10.4.82006-11-27
CVE-2006-6127 [LOW] CVE-2006-6127: Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.
nvd
CVE-2004-0923P4LOWCVSS 2.1v10.2v10.2.1+13 more2005-01-27
CVE-2004-0923 [LOW] CVE-2004-0923: CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, w
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.
nvd
CVE-2006-6126P4LOWCVSS 2.1v10.4.82006-11-27
CVE-2006-6126 [LOW] CVE-2006-6126: Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mac
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.
nvd
CVE-2005-2509P4LOWCVSS 2.1v10.0v10.1+26 more2005-08-19
CVE-2005-2509 [LOW] CVE-2005-2509: Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is ena
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.
nvd
CVE-2011-3212P4LOWCVSS 2.1v10.7.0v10.7.12011-10-14
CVE-2011-3212 [LOW] CWE-310 CVE-2011-3212: CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted dur
CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device.
nvd
CVE-2004-1087P4LOWCVSS 2.1v10.2v10.2.1+14 more2004-12-02
CVE-2004-1087 [LOW] CVE-2004-1087: Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.
nvd
CVE-2005-2750P4LOWCVSS 2.1v10.4.22005-11-01
CVE-2005-2750 [LOW] CVE-2005-2750: Software Update in Mac OS X 10.4.2, when the user marks all updates to be ignored, exits without ask
Software Update in Mac OS X 10.4.2, when the user marks all updates to be ignored, exits without asking the user to reset the status of the updates, which could prevent important, security-relevant updates from being installed.
nvd
CVE-2009-0014P4LOWCVSS 2.1v10.5.62009-02-13
CVE-2009-0014 [LOW] CWE-264 CVE-2009-0014: Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Download
Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.
nvd
CVE-2004-1081P4LOWCVSS 2.1v10.2v10.2.1+14 more2004-12-02
CVE-2004-1081 [LOW] CVE-2004-1081: The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict a
The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.
nvd
CVE-2004-1085P4LOWCVSS 2.1v10.2v10.2.1+14 more2004-12-02
CVE-2004-1085 [LOW] CVE-2004-1085: Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit application
Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.
nvd