Apple Os X Server vulnerabilities

11 known vulnerabilities affecting apple/os_x_server.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM6LOW2

Vulnerabilities

Page 1 of 1
CVE-2016-4694CRITICALCVSS 9.1≤ 5.12016-09-25
CVE-2016-4694 [CRITICAL] CWE-284 CVE-2016-4694: The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 sectio The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy ser
nvd
CVE-2016-4754HIGHCVSS 7.5≤ 5.12016-09-25
CVE-2016-4754 [HIGH] CWE-310 CVE-2016-4754: ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
nvd
CVE-2015-1151MEDIUMCVSS 5.0≤ 4.02015-04-28
CVE-2015-1151 [MEDIUM] CWE-284 CVE-2015-1151: Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client.
nvd
CVE-2015-1150MEDIUMCVSS 5.0≤ 4.02015-04-28
CVE-2015-1150 [MEDIUM] CWE-17 CVE-2015-1150: The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration f The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration files, which allows remote attackers to bypass network-access restrictions by sending packets for which custom-rule blocking was intended.
nvd
CVE-2014-3583MEDIUMCVSS 5.0v5.0.32014-12-15
CVE-2014-3583 [MEDIUM] CWE-119 CVE-2014-3583: The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Serv The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
nvd
CVE-2014-4447LOWCVSS 1.9≤ 3.1.22014-10-18
CVE-2014-4447 [LOW] CWE-310 CVE-2014-4447: Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords b Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file after a (1) profile setup or (2) profile edit occurs.
nvd
CVE-2014-4446LOWCVSS 2.1≤ 3.1.22014-10-18
CVE-2014-4446 [LOW] CWE-264 CVE-2014-4446: Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service res Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a change made by an administrator.
nvd
CVE-2014-4424HIGHCVSS 7.5≤ 2.2.2v2.0+11 more2014-09-19
CVE-2014-4424 [HIGH] CWE-89 CVE-2014-4424: SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 an SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2014-4406MEDIUMCVSS 6.1≤ 3.1.2v2.0+11 more2014-09-19
CVE-2014-4406 [MEDIUM] CWE-79 CVE-2014-4406: Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server b Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-5143MEDIUMCVSS 6.8≤ 2.2.2v2.0+4 more2013-10-24
CVE-2013-5143 [MEDIUM] CVE-2013-5143: The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificat The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified circumstances, which might allow man-in-the-middle attackers to hijack RADIUS sessions by leveraging knowledge of the private key that matches this fallback certificate.
nvd
CVE-2013-1034MEDIUMCVSS 4.3≤ 2.2.1v2.0+3 more2013-09-19
CVE-2013-1034 [MEDIUM] CWE-79 CVE-2013-1034: Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2 Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd