Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 6 of 33
CVE-2008-3621P3CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-3621 [CRITICAL] CWE-399 CVE-2008-3621: VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a
VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving H.264 encoded media.
nvd
CVE-2011-3453P3HIGHCVSS 7.5≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3453 [HIGH] CWE-189 CVE-2011-3453: Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arb
Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via crafted DNS data.
nvd
CVE-2009-0018P3HIGHCVSS 7.8v10.4.11v10.5.62009-02-13
CVE-2009-0018 [HIGH] CWE-119 CVE-2009-0018: The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a b
The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.
nvd
CVE-2010-1816P3HIGHCVSS 7.8v10.6.0v10.6.1+2 more2017-04-13
CVE-2010-1816 [HIGH] CWE-119 CVE-2010-1816: Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10
Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.
nvd
CVE-2010-0533P3HIGHCVSS 7.5≤ 10.6.2v10.6.0+1 more2010-03-30
CVE-2010-0533 [HIGH] CWE-22 CVE-2010-0533: Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attack
Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and modify files in that directory, via unspecified vectors.
nvd
CVE-2008-4211P3CRITICALCVSS 10.0v10.5.52008-10-10
CVE-2008-4211 [CRITICAL] CWE-189 CVE-2008-4211: Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iP
Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory acc
nvd
CVE-2007-4702P3CRITICALCVSS 9.3v10.52007-11-15
CVE-2007-4702 [CRITICAL] CVE-2007-4702: The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, d
The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.
nvd
CVE-2003-1009P3CRITICALCVSS 10.0v10.2v10.2.1+10 more2004-03-29
CVE-2003-1009 [CRITICAL] CVE-2003-1009: Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 t
Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.
nvd
CVE-2008-4220P3CRITICALCVSS 10.0≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4220 [CRITICAL] CWE-189 CVE-2008-4220: Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows contex
Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. NOTE: this may be related to the WLB-2008080064 advisory published by SecurityReason on 20080822; however, as of 20081216, there
nvd
CVE-2008-3616P3CRITICALCVSS 10.0v10.4.11v10.5+4 more2008-09-16
CVE-2008-3616 [CRITICAL] CWE-189 CVE-2008-3616: Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 al
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
nvd
CVE-2012-0662P3HIGHCVSS 7.5≤ 10.7.3v10.0+68 more2012-05-11
CVE-2012-0662 [HIGH] CWE-189 CVE-2012-0662: Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers t
Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.
nvd
CVE-2008-2311P3HIGHCVSS 7.6v10.4.1v10.4.2+13 more2008-07-01
CVE-2008-2311 [HIGH] CWE-59 CVE-2008-2311: Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attack
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.
nvd
CVE-2011-3457P3HIGHCVSS 7.5≤ 10.7.2v10.6.0+10 more2012-02-02
CVE-2011-3457 [HIGH] CWE-119 CVE-2011-3457: The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading L
The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted program.
nvd
CVE-2012-0650P3HIGHCVSS 7.5≤ 10.6.8v10.0+64 more2012-09-20
CVE-2012-0650 [HIGH] CWE-119 CVE-2012-0650: Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 a
Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2008-4237P3CRITICALCVSS 10.0≤ 10.5.5v10.5+4 more2008-12-17
CVE-2008-4237 [CRITICAL] CVE-2008-4237: Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-
Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context-dependent attackers to have an unspecified impact by leveraging unintended settings, as demonstrated by the screen saver lock setting.
nvd
CVE-2005-2511P3CRITICALCVSS 10.0v10.4.22005-08-19
CVE-2005-2511 [CRITICAL] CVE-2005-2511: Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP,
Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, allows attackers to gain access to a root Terminal window.
nvd
CVE-2009-0139P3CRITICALCVSS 9.3v10.5.62009-02-13
CVE-2009-0139 [CRITICAL] CWE-189 CVE-2009-0139: Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a
Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.
nvd
CVE-2010-0057P3HIGHCVSS 7.5≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0057 [HIGH] CWE-264 CVE-2010-0057: AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest acces
AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request.
nvd
CVE-2004-1307P3HIGHCVSS 7.5v10.3v10.3.1+8 more2004-12-21
CVE-2004-1307 [HIGH] CVE-2004-1307: Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remot
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
nvd
CVE-2007-4687P3CRITICALCVSS 9.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4687 [CRITICAL] CWE-16 CVE-2007-4687: The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the t
The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.
nvd