Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Apple Subscribe
Filtered by product Mac Os X Server
Total 799 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0975 1 Apple 3 Mac Os X, Mac Os X Server, Safari 2017-07-10 5.0 MEDIUM N/A
Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
CVE-2003-0601 1 Apple 1 Mac Os X Server 2017-07-10 7.5 HIGH N/A
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.
CVE-2003-0420 1 Apple 1 Mac Os X Server 2017-07-10 4.6 MEDIUM N/A
Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.
CVE-2010-1816 1 Apple 2 Mac Os X, Mac Os X Server 2017-04-21 9.3 HIGH 7.8 HIGH
Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.
CVE-2010-1821 1 Apple 2 Mac Os X, Mac Os X Server 2017-04-20 7.2 HIGH 7.8 HIGH
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
CVE-2015-5986 2 Apple, Isc 2 Mac Os X Server, Bind 2016-12-30 7.1 HIGH N/A
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
CVE-2015-5722 2 Apple, Isc 2 Mac Os X Server, Bind 2016-12-30 7.8 HIGH N/A
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
CVE-2015-7031 1 Apple 1 Mac Os X Server 2016-12-23 5.0 MEDIUM N/A
The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.
CVE-2015-5911 1 Apple 1 Mac Os X Server 2016-12-21 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.
CVE-2016-1777 1 Apple 1 Mac Os X Server 2016-12-19 5.0 MEDIUM 7.5 HIGH
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
CVE-2016-1787 1 Apple 1 Mac Os X Server 2016-12-19 5.0 MEDIUM 5.3 MEDIUM
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
CVE-2016-1774 1 Apple 1 Mac Os X Server 2016-12-19 5.0 MEDIUM 5.3 MEDIUM
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.
CVE-2016-1776 1 Apple 1 Mac Os X Server 2016-12-19 5.0 MEDIUM 5.3 MEDIUM
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.
CVE-2014-1370 1 Apple 2 Mac Os X, Mac Os X Server 2016-12-07 6.8 MEDIUM N/A
The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.
CVE-2014-1269 1 Apple 4 Mac Os X, Mac Os X Server, Safari and 1 more 2016-12-07 6.8 MEDIUM N/A
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
CVE-2014-1268 1 Apple 4 Mac Os X, Mac Os X Server, Safari and 1 more 2016-12-07 6.8 MEDIUM N/A
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270.
CVE-2014-1270 1 Apple 4 Mac Os X, Mac Os X Server, Safari and 1 more 2016-12-07 6.8 MEDIUM N/A
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
CVE-2005-1725 1 Apple 1 Mac Os X Server 2016-10-17 2.1 LOW N/A
launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.
CVE-2009-0158 1 Apple 2 Mac Os X, Mac Os X Server 2016-08-22 6.8 MEDIUM N/A
Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.
CVE-2005-2741 2 Apple, Perry Kiehtreiber 3 Mac Os X, Mac Os X Server, Securityd 2016-05-09 7.2 HIGH N/A
Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators.