← Back

Mac Os X Server

mac_os_x_server

Vendor: Apple • 655 CVEs

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
May 13, 2026
Apr 13, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
1Apple
2Mac Os X
Mac Os X Server
May 13, 2026
Apr 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.
1Apple
1Mac Os X Server
May 6, 2026
Mar 24, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
1Apple
1Mac Os X Server
May 6, 2026
Mar 24, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
1Apple
1Mac Os X Server
May 6, 2026
Mar 24, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.
1Apple
1Mac Os X Server
May 6, 2026
Mar 24, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in oppo...Show more
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.Show less
1Apple
1Mac Os X Server
May 6, 2026
Oct 23, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.
1Apple
1Mac Os X Server
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.
2Apple
Isc
2Bind
Mac Os X Server
May 6, 2026
Sep 5, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
2Apple
Isc
2Bind
Mac Os X Server
May 6, 2026
Sep 5, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key...Show more
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.Show less
3Apache
AppleCanonical
5Http Server
Mac Os XMac Os X Server+2 more
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authenticatio...Show more
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.Show less
3Apache
AppleOracle
5Http Server
LinuxMac Os X+2 more
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference...Show more
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI.Show less
4Apple
CanonicalDebian+1 more
4Debian Linux
Mac Os X ServerPostgresql+1 more
May 6, 2026
May 28, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL s...Show more
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.Show less
4Apache
AppleCanonical+1 more
5Http Server
Mac Os XMac Os X Server+2 more
May 6, 2026
Mar 8, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Pi...Show more
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.Show less
1Apple
2Mac Os X
Mac Os X Server
May 6, 2026
Sep 19, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.
1Apple
2Mac Os X
Mac Os X Server
May 6, 2026
Sep 19, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.
1Apple
2Mac Os X
Mac Os X Server
May 6, 2026
Jul 1, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandb...Show more
Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.Show less
1Apple
2Mac Os X
Mac Os X Server
May 6, 2026
Jul 1, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted Ap...Show more
The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.Show less
1Apple
4Iphone Os
Mac Os XMac Os X Server+1 more
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to...Show more
CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.Show less
5Apache
AppleCanonical+2 more
15Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+12 more
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the...Show more
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."Show less