Apple Mac Os X Server vulnerabilities

654 known vulnerabilities affecting apple/mac_os_x_server.

Total CVEs
654
CISA KEV
0
Public exploits
49
Exploited in wild
0
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59

Vulnerabilities

Page 6 of 33
CVE-2011-0212MEDIUMCVSS 6.4v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0212 [MEDIUM] CWE-399 CVE-2011-0212: servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and poss servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
nvd
CVE-2011-0198MEDIUMCVSS 6.8v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0198 [MEDIUM] CWE-119 CVE-2011-0198: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remot Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font.
nvd
CVE-2011-0199MEDIUMCVSS 5.9≥ 10.6.0, < 10.6.82011-06-24
CVE-2011-0199 [MEDIUM] CWE-295 CVE-2011-0199: The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.
nvd
CVE-2011-0207MEDIUMCVSS 5.0v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0207 [MEDIUM] CWE-310 CVE-2011-0207: The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail ap The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network.
nvd
CVE-2011-0202MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0202 [MEDIUM] CWE-189 CVE-2011-0202: Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.
nvd
CVE-2011-0204MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0204 [MEDIUM] CWE-119 CVE-2011-0204: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to exe Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image.
nvd
CVE-2011-1132MEDIUMCVSS 4.9v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-1132 [MEDIUM] CVE-2011-1132: The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.
nvd
CVE-2011-0205MEDIUMCVSS 6.8v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0205 [MEDIUM] CWE-119 CVE-2011-0205: Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to exe Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.
nvd
CVE-2011-0200MEDIUMCVSS 6.8v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0200 [MEDIUM] CWE-189 CVE-2011-0200: Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arb Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.
nvd
CVE-2011-0208MEDIUMCVSS 6.8v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0208 [MEDIUM] CWE-119 CVE-2011-0208: QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.
nvd
CVE-2011-0197LOWCVSS 2.1v10.5.8v10.6.0+7 more2011-06-24
CVE-2011-0197 [LOW] CWE-200 CVE-2011-0197: App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.
nvd
CVE-2011-1755HIGHCVSS 7.5fixed in 10.6.8≥ 10.7.0, < 10.7.22011-06-21
CVE-2011-1755 [HIGH] CVE-2011-1755: jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remo jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
nvd
CVE-2011-0182HIGHCVSS 7.2PoC≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0182 [HIGH] CWE-20 CVE-2011-0182: The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.
nvd
CVE-2011-0174MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0174 [MEDIUM] CWE-119 CVE-2011-0174: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remot Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
nvd
CVE-2011-0176MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0176 [MEDIUM] CWE-119 CVE-2011-0176: Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.
nvd
CVE-2011-0189MEDIUMCVSS 5.0v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0189 [MEDIUM] CWE-16 CVE-2011-0189: The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulnerabilities.
nvd
CVE-2011-0181MEDIUMCVSS 6.8≤ 10.6.6v10.5.8+6 more2011-03-23
CVE-2011-0181 [MEDIUM] CWE-189 CVE-2011-0181: Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbit Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image.
nvd
CVE-2011-0177MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0177 [MEDIUM] CWE-119 CVE-2011-0177: Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.
nvd
CVE-2011-0194MEDIUMCVSS 6.8v10.6.0v10.6.1+5 more2011-03-23
CVE-2011-0194 [MEDIUM] CWE-189 CVE-2011-0194: Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.
nvd
CVE-2011-0173MEDIUMCVSS 6.8≤ 10.6.6v10.6.0+5 more2011-03-23
CVE-2011-0173 [MEDIUM] CWE-134 CVE-2011-0173: Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context- Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.
nvd