Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 8 of 33
CVE-2009-0942P3MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0942 [MEDIUM] CWE-20 CVE-2009-0942: Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.
nvd
CVE-2008-3608P4CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-3608 [CRITICAL] CWE-399 CVE-2008-3608: ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to caus
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
nvd
CVE-2008-2332P3CRITICALCVSS 9.3v10.4.11v10.5+4 more2008-09-16
CVE-2008-2332 [CRITICAL] CWE-399 CVE-2008-2332: ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to caus
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
nvd
CVE-2010-0524P3HIGHCVSS 7.5v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0524 [HIGH] CWE-264 CVE-2010-0524: The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EA
The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.
nvd
CVE-2015-0228P4MEDIUMCVSS 5.0v5.0.32015-03-08
CVE-2015-0228 [MEDIUM] CWE-20 CVE-2015-0228: The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server thr
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
nvd
CVE-2006-4095P4HIGHCVSS 7.5fixed in 10.3.9≥ 10.4.0, < 10.4.92006-09-06
CVE-2006-4095 [HIGH] CWE-617 CVE-2006-4095: BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
nvd
CVE-2011-0229P3MEDIUMCVSS 6.8≤ 10.6.8v10.0+64 more2011-10-14
CVE-2011-0229 [MEDIUM] CWE-119 CVE-2011-0229: Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1
Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access.
nvd
CVE-2011-3226P3MEDIUMCVSS 6.8v10.7.0v10.7.12011-10-14
CVE-2011-3226 [MEDIUM] CWE-264 CVE-2011-3226: Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or
Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account.
nvd
CVE-2009-0140P4CRITICALCVSS 9.3v10.4.11v10.5.62009-02-13
CVE-2009-0140 [CRITICAL] CWE-399 CVE-2009-0140: Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SM
Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.
nvd
CVE-2004-0926P4CRITICALCVSS 10.0v10.2v10.2.1+13 more2005-01-27
CVE-2004-0926 [CRITICAL] CVE-2004-0926: Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attac
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
nvd
CVE-2013-0966P3MEDIUMCVSS 6.4v10.6.8v10.7.0+5 more2013-03-15
CVE-2013-0966 [MEDIUM] CVE-2013-0966: The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not p
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
nvd
CVE-2005-2743P4HIGHCVSS 7.5v10.3.92005-10-26
CVE-2005-2743 [HIGH] CVE-2005-2743: The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
nvd
CVE-2005-0342P4LOWCVSS 2.1PoCv10.0v10.1+22 more2005-05-02
CVE-2005-0342 [LOW] CVE-2005-0342: The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileg
The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.
nvd
CVE-2005-2508P4MEDIUMCVSS 4.6PoCv10.4.22005-08-19
CVE-2005-2508 [MEDIUM] CVE-2005-2508: dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user account
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.
nvd
CVE-2009-1728P3MEDIUMCVSS 6.8v10.5v10.5.0+20 more2009-08-06
CVE-2009-1728 [MEDIUM] CWE-119 CVE-2009-1728: Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digit
Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.
nvd
CVE-2009-0154P3MEDIUMCVSS 6.8v10.4.11v10.5.0+6 more2009-05-13
CVE-2009-0154 [MEDIUM] CWE-119 CVE-2009-0154: Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.
nvd
CVE-2009-2828P3HIGHCVSS 7.5v10.5.82009-11-10
CVE-2009-2828 [HIGH] CWE-399 CVE-2009-2828: The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary
The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2008-1028P4CRITICALCVSS 9.3v10.4.112008-06-02
CVE-2008-1028 [CRITICAL] CWE-20 CVE-2008-1028: Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attack
Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.
nvd
CVE-2010-0500P4HIGHCVSS 7.8≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0500 [HIGH] CWE-20 CVE-2010-0500: Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, w
Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."
nvd
CVE-2014-1391P4MEDIUMCVSS 6.8v10.7.52014-09-19
CVE-2014-1391 [MEDIUM] CWE-119 CVE-2014-1391: QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.
nvd