Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 33 of 33
CVE-2003-0804MEDIUMCVSS 5.0v10.2v10.2.1+6 more2003-11-17
CVE-2003-0804 [MEDIUM] CVE-2003-0804: The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-ba
The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.
nvd
CVE-2003-0871HIGHCVSS 7.5v10.32003-11-03
CVE-2003-0871 [HIGH] CVE-2003-0871: Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."
nvd
CVE-2003-0876LOWCVSS 2.1v10.0v10.2+8 more2003-11-03
CVE-2003-0876 [LOW] CVE-2003-0876: Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.
nvd
CVE-2003-0694CRITICALCVSS 10.0PoCv10.2v10.2.1+5 more2003-10-06
CVE-2003-0694 [CRITICAL] CVE-2003-0694: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
nvd
CVE-2003-0681HIGHCVSS 7.5PoCv10.2v10.2.1+5 more2003-10-06
CVE-2003-0681 [HIGH] CVE-2003-0681: A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rul
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
nvd
CVE-2003-0466CRITICALCVSS 9.8PoCv10.2.62003-08-27
CVE-2003-0466 [CRITICAL] CWE-193 CVE-2003-0466: Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may al
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU
nvd
CVE-2003-0518MEDIUMCVSS 4.6v10.2v10.2.1+5 more2003-08-18
CVE-2003-0518 [MEDIUM] CVE-2003-0518: The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.
nvd
CVE-2003-0420MEDIUMCVSS 4.6v10.2.62003-06-13
CVE-2003-0420 [MEDIUM] CVE-2003-0420: Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obta
Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.
nvd
CVE-2003-0171HIGHCVSS 7.2PoCv10.0v10.2+4 more2003-05-05
CVE-2003-0171 [HIGH] CVE-2003-0171: DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch co
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
nvd
CVE-2003-0198MEDIUMCVSS 6.4v10.0v10.2+4 more2003-05-05
CVE-2003-0198 [MEDIUM] CVE-2003-0198: Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read u
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
nvd
CVE-2003-0049HIGHCVSS 7.5v10.2v10.2.1+2 more2003-03-03
CVE-2003-0049 [HIGH] CVE-2003-0049: Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users b
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
nvd
CVE-2002-1347CRITICALCVSS 9.8fixed in 10.3.82002-12-18
CVE-2002-1347 [CRITICAL] CWE-131 CVE-2002-1347: Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not
nvd
CVE-2002-1265MEDIUMCVSS 5.0v10.0v10.2+1 more2002-11-12
CVE-2002-1265 [MEDIUM] CVE-2002-1265: The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism whe
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
nvd
CVE-2002-0666MEDIUMCVSS 5.0v10.22002-11-04
CVE-2002-0666 [MEDIUM] CVE-2002-0666: IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of a
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
nvd
← Previous33 / 33