Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 5 of 33
CVE-2010-1377P3CRITICALCVSS 9.3v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1377 [CRITICAL] CWE-310 CVE-2010-1377: Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain S
Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors.
nvd
CVE-2008-1030P3CRITICALCVSS 10.0v10.4.11v10.5+2 more2008-06-02
CVE-2008-1030 [CRITICAL] CWE-20 CVE-2008-1030: Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac
Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.
nvd
CVE-2008-3642P3CRITICALCVSS 9.3v10.4.11v10.5.52008-10-10
CVE-2008-3642 [CRITICAL] CWE-119 CVE-2008-3642: Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denia
Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
nvd
CVE-2007-0736P3CRITICALCVSS 9.3v10.3.9v10.4+9 more2007-04-24
CVE-2007-0736 [CRITICAL] CVE-2007-0736: Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote
Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.
nvd
CVE-2007-0731P3CRITICALCVSS 9.3v10.4v10.4.1+7 more2007-03-13
CVE-2007-0731 [CRITICAL] CVE-2007-0731: Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 1
Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.
nvd
CVE-2010-1841P3CRITICALCVSS 9.3v10.5.8v10.6.0+4 more2010-11-15
CVE-2010-1841 [CRITICAL] CWE-20 CVE-2010-1841: Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arb
Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.
nvd
CVE-2007-4703P3CRITICALCVSS 10.0v10.52007-11-15
CVE-2007-4703 [CRITICAL] CVE-2007-4703: The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incom
The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.
nvd
CVE-2008-3610P3HIGHCVSS 7.6v10.5v10.5.1+3 more2008-09-16
CVE-2008-3610 [HIGH] CWE-287 CVE-2008-3610: Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
nvd
CVE-2004-0803P3HIGHCVSS 7.5v10.2v10.2.1+14 more2004-12-23
CVE-2004-0803 [HIGH] CVE-2004-0803: Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, re
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
nvd
CVE-2006-6061P3CRITICALCVSS 9.3v10.4.82006-11-22
CVE-2006-6061 [CRITICAL] CVE-2006-6061: com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows rem
com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity of this issue has been disputed by a third party, who states that the impact is limited to a denial of service (kernel panic) due to a vm_fau
nvd
CVE-2007-4690P3CRITICALCVSS 9.0v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4690 [CRITICAL] CWE-399 CVE-2007-4690: Double free vulnerability in the NFS component in Apple Mac OS X 10.4 through 10.4.10 allows remote
Double free vulnerability in the NFS component in Apple Mac OS X 10.4 through 10.4.10 allows remote authenticated users to execute arbitrary code via a crafted AUTH_UNIX RPC packet.
nvd
CVE-2012-3489P3MEDIUMCVSS 6.5≥ 10.7.0, ≤ 10.7.5v10.6.82012-10-03
CVE-2012-3489 [MEDIUM] CWE-611 CVE-2012-3489: The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers
nvd
CVE-2007-0723P3HIGHCVSS 8.5v10.3.9v10.4+8 more2007-03-13
CVE-2007-0723 [HIGH] CVE-2007-0723: Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple
Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors.
nvd
CVE-2010-0510P3CRITICALCVSS 9.0≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0510 [CRITICAL] CWE-255 CVE-2010-0510: Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replicatio
Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users to obtain login access via an expired password.
nvd
CVE-2008-1574P3CRITICALCVSS 9.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1574 [CRITICAL] CWE-119 CVE-2008-1574: Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbit
Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow.
nvd
CVE-2010-1411P3MEDIUMCVSS 6.8v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-1411 [MEDIUM] CWE-189 CVE-2010-1411: Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTI
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer ove
nvd
CVE-2010-0504P3HIGHCVSS 7.5≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0504 [HIGH] CWE-119 CVE-2010-0504: Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow r
Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2005-2507P3HIGHCVSS 7.5v10.3.9v10.4.22005-08-19
CVE-2005-2507 [HIGH] CVE-2005-2507: Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execu
Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
nvd
CVE-2010-0522P3CRITICALCVSS 9.0v10.5.82010-03-30
CVE-2010-0522 [CRITICAL] CWE-264 CVE-2010-0522: Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who
Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which allows remote authenticated users to leverage this former membership to obtain a server connection via screen sharing.
nvd
CVE-2006-4866P4MEDIUMCVSS 4.6PoCv10.0v10.1+32 more2006-09-19
CVE-2006-4866 [MEDIUM] CVE-2006-4866: Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possib
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
nvd