Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 4 of 33
CVE-2006-1470P4MEDIUMCVSS 5.0PoCv10.4v10.4.1+5 more2006-06-27
CVE-2006-1470 [MEDIUM] CWE-399 CVE-2006-1470: OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (c
OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.
nvd
CVE-2007-2399P3CRITICALCVSS 9.3v10.3.9v10.4.92007-06-25
CVE-2007-2399 [CRITICAL] CVE-2007-2399: WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type
WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.
nvd
CVE-2015-3185P3MEDIUMCVSS 4.3v5.0.32015-07-20
CVE-2015-3185 [MEDIUM] CWE-264 CVE-2015-3185: The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the pres
nvd
CVE-2008-1575P3CRITICALCVSS 9.3v10.5v10.5.1+1 more2008-06-02
CVE-2008-1575 [CRITICAL] CWE-399 CVE-2008-1575: Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5
Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a crafted embedded font in a PDF document, related to memory corruption that occurs during printing.
nvd
CVE-2008-3637P3HIGHCVSS 8.8v10.4.11v10.5.4+1 more2008-09-26
CVE-2008-3637 [HIGH] CWE-665 CVE-2008-3637: The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4
The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an "error checking issue."
nvd
CVE-2008-4212P3CRITICALCVSS 10.0v10.4.11v10.5.52008-10-10
CVE-2008-4212 [CRITICAL] CWE-16 CVE-2008-4212: Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which might allow remote attackers to bypass intended access restrictions.
nvd
CVE-2007-4689P3CRITICALCVSS 10.0v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4689 [CRITICAL] CWE-399 CVE-2007-4689: Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows
Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.
nvd
CVE-2015-5986P3HIGHCVSS 7.1v5.0.152015-09-05
CVE-2015-5986 [HIGH] CWE-20 CVE-2015-5986: openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
nvd
CVE-2009-2188P3CRITICALCVSS 9.3v10.5v10.5.0+7 more2009-08-06
CVE-2009-2188 [CRITICAL] CWE-119 CVE-2009-2188: Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows rem
Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with crafted EXIF metadata.
nvd
CVE-2010-0512P3CRITICALCVSS 9.3v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0512 [CRITICAL] CWE-264 CVE-2010-0512: The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account
The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.
nvd
CVE-2006-6129P4MEDIUMCVSS 4.6PoCv10.4.82006-11-27
CVE-2006-6129 [MEDIUM] CVE-2006-6129: Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of s
Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.
nvd
CVE-2010-1842P3CRITICALCVSS 9.3v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1842 [CRITICAL] CWE-119 CVE-2010-1842: Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute
Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a bidirectional text string with ellipsis truncation.
nvd
CVE-2008-4234P3CRITICALCVSS 9.3≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4234 [CRITICAL] CWE-264 CVE-2008-4234: Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 bef
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application association for the file, which does not trigger a "potentially unsafe" warning message.
nvd
CVE-2015-5911P3CRITICALCVSS 10.0≤ 5.0.22015-09-18
CVE-2015-5911 [CRITICAL] CVE-2015-5911: Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 all
Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.
nvd
CVE-2012-3716P3HIGHCVSS 7.5v10.7.0v10.7.1+3 more2012-09-20
CVE-2012-3716 [HIGH] CWE-119 CVE-2012-3716: CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or
CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.
nvd
CVE-2004-0539P3CRITICALCVSS 10.0v10.2.8v10.3.42004-08-06
CVE-2004-0539 [CRITICAL] CVE-2004-0539: The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute down
The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.
nvd
CVE-2005-1689P3CRITICALCVSS 9.8fixed in 10.4.22005-07-18
CVE-2005-1689 [CRITICAL] CWE-415 CVE-2005-1689: Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier a
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
nvd
CVE-2008-3647P3CRITICALCVSS 9.3v10.4.11v10.5.52008-10-10
CVE-2008-3647 [CRITICAL] CWE-119 CVE-2008-3647: Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a de
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.
nvd
CVE-2010-0037P3HIGHCVSS 8.8v10.5.8v10.6.22010-01-20
CVE-2010-0037 [HIGH] CWE-119 CVE-2010-0037: Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute
Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted DNG image.
nvd
CVE-2016-1777P3HIGHCVSS 7.5≤ 5.0.152016-03-24
CVE-2016-1777 [HIGH] CWE-310 CVE-2016-1777: Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for rem
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
nvd