Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 7 of 33
CVE-2006-1456P3HIGHCVSS 7.5v10.3.9v10.4.62006-05-12
CVE-2006-1456 [HIGH] CVE-2006-1456: Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote atta
Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.
nvd
CVE-2010-1820P3MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-09-21
CVE-2010-1820 [MEDIUM] CWE-287 CVE-2010-1820: Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle
Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.
nvd
CVE-2011-3436P3MEDIUMCVSS 6.5v10.7.0v10.7.12011-10-14
CVE-2011-3436 [MEDIUM] CWE-264 CVE-2011-3436: Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current p
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.
nvd
CVE-2008-1031P3CRITICALCVSS 9.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1031 [CRITICAL] CWE-119 CVE-2008-1031: CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or ca
CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable.
nvd
CVE-2008-1577P3CRITICALCVSS 9.3v10.4.11v10.5+2 more2008-06-02
CVE-2008-1577 [CRITICAL] CVE-2008-1577: Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3
Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues."
nvd
CVE-2011-0230P3HIGHCVSS 7.5≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-0230 [HIGH] CWE-119 CVE-2011-0230: Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 1
Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2007-3744P3MEDIUMCVSS 5.8v10.4v10.4.1+9 more2007-08-03
CVE-2007-3744 [MEDIUM] CWE-119 CVE-2007-3744: Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Prot
Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
nvd
CVE-2011-0198P3MEDIUMCVSS 6.8v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0198 [MEDIUM] CWE-119 CVE-2011-0198: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remot
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font.
nvd
CVE-2010-1821P3HIGHCVSS 7.8v10.6.0v10.6.1+2 more2017-04-13
CVE-2010-1821 [HIGH] CWE-20 CVE-2010-1821: Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obt
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
nvd
CVE-2009-2819P3CRITICALCVSS 9.3v10.5.82009-11-10
CVE-2009-2819 [CRITICAL] CWE-399 CVE-2009-2819: AFP Client in Apple Mac OS X 10.5.8 allows remote AFP servers to execute arbitrary code or cause a d
AFP Client in Apple Mac OS X 10.5.8 allows remote AFP servers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via unspecified vectors.
nvd
CVE-2009-1237P4MEDIUMCVSS 4.9PoC≤ 10.5.6v10.0+53 more2009-04-02
CVE-2009-1237 [MEDIUM] CWE-399 CVE-2009-1237: Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.
nvd
CVE-2005-0713P4MEDIUMCVSS 4.6PoCv10.3v10.3.1+6 more2005-03-21
CVE-2005-0713 [MEDIUM] CVE-2005-0713: The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluet
The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.
nvd
CVE-2011-3460P3HIGHCVSS 7.5≤ 10.7.2v10.6.0+10 more2012-02-02
CVE-2011-3460 [HIGH] CWE-119 CVE-2011-3460: Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbi
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PNG file.
nvd
CVE-2008-4221P3CRITICALCVSS 10.0≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4221 [CRITICAL] CWE-399 CVE-2008-4221: The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to
The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted date string, related to improper memory allocation.
nvd
CVE-2011-1755P3HIGHCVSS 7.5fixed in 10.6.8≥ 10.7.0, < 10.7.22011-06-21
CVE-2011-1755 [HIGH] CVE-2011-1755: jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remo
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
nvd
CVE-2010-1380P3HIGHCVSS 7.5v10.6.0v10.6.1+2 more2010-06-17
CVE-2010-1380 [HIGH] CWE-189 CVE-2010-1380: Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allo
Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page sizes.
nvd
CVE-2010-3787P3MEDIUMCVSS 6.8v10.6.0v10.6.1+3 more2010-11-16
CVE-2010-3787 [MEDIUM] CWE-119 CVE-2010-3787: Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attacke
Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.
nvd
CVE-2011-0206P3HIGHCVSS 7.5v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0206 [HIGH] CWE-119 CVE-2011-0206: Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows
Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.
nvd
CVE-2011-3446P3HIGHCVSS 7.5≤ 10.7.2v10.7.0+1 more2012-02-02
CVE-2011-3446 [HIGH] CVE-2011-3446: Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-f
Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.
nvd
CVE-2007-0750P4CRITICALCVSS 9.3v10.4v10.4.1+8 more2007-05-24
CVE-2007-0750 [CRITICAL] CVE-2007-0750: Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted att
Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.
nvd