Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 33 of 33
CVE-2009-0013P4LOWCVSS 2.1v10.4.11v10.5.62009-02-13
CVE-2009-0013 [LOW] CWE-255 CVE-2009-0013: dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as co
dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.
nvd
CVE-2005-0715P4LOWCVSS 2.1v10.3v10.3.1+6 more2005-03-21
CVE-2005-0715 [LOW] CVE-2005-0715: AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local
AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box.
nvd
CVE-2009-0142P4LOWCVSS 1.9v10.5.62009-02-12
CVE-2009-0142 [LOW] CWE-362 CVE-2009-0142: Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of servic
Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic."
nvd
CVE-2006-0386P4LOWCVSS 1.7v10.3v10.3.1+14 more2006-03-03
CVE-2006-0386 [LOW] CVE-2006-0386: FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a Fi
FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.
nvd
CVE-2005-2749P4LOWCVSS 2.1v10.4v10.4.1+1 more2005-11-01
CVE-2005-2749 [LOW] CVE-2005-2749: Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder
Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder to misrepresent file and group ownership information. NOTE: it is not clear whether this issue satisfies the CVE definition of a vulnerability.
nvd
CVE-2011-3216P4LOWCVSS 2.1≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3216 [LOW] CWE-264 CVE-2011-3216: The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directorie
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.
nvd
CVE-2007-4701P4LOWCVSS 2.1v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4701 [LOW] CWE-264 CVE-2007-4701: WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari i
WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.
nvd
CVE-2011-0178P4LOWCVSS 2.1≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0178 [LOW] CWE-200 CVE-2011-0178: The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directo
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
nvd
CVE-2008-0996P4LOWCVSS 1.7v10.5.22008-03-18
CVE-2008-0996 [LOW] CWE-200 CVE-2008-0996: The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when s
The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when starting a job on an authenticated print queue, which might allow local users to obtain the credentials.
nvd
CVE-2008-3619P4LOWCVSS 2.1v10.5v10.5.1+3 more2008-09-16
CVE-2008-3619 [LOW] CWE-264 CVE-2008-3619: Time Machine in Apple Mac OS X 10.5 through 10.5.4 uses weak permissions for Time Machine Backup log
Time Machine in Apple Mac OS X 10.5 through 10.5.4 uses weak permissions for Time Machine Backup log files, which allows local users to obtain sensitive information by reading these files.
nvd
CVE-2006-3499P4LOWCVSS 2.1v10.3.92006-08-03
CVE-2006-3499 [LOW] CVE-2006-3499: The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive informatio
The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error (stderr) by privileged applications.
nvd
CVE-2011-0197P4LOWCVSS 2.1v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0197 [LOW] CWE-200 CVE-2011-0197: App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password,
App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.
nvd
CVE-2007-0751P4LOWCVSS 2.1v10.3v10.3.1+18 more2007-05-24
CVE-2007-0751 [LOW] CVE-2007-0751: A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.
nvd
CVE-2008-1578P4LOWCVSS 2.1v10.4.11v10.5+2 more2008-06-02
CVE-2008-1578 [LOW] CWE-200 CVE-2008-1578: The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the comma
The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process.
nvd
← Previous33 / 33