← Back

Mac Os X Server

mac_os_x_server

Vendor: Apple • 655 CVEs

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.
1Apple
3Carboncore
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive in...Show more
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
1Apple
3Applescript
Mac Os XMac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifi...Show more
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
4.9 MEDIUM· v2
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-...Show more
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.Show less
1Apple
3Iphone Os
Mac Os XMac Os X Server
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (me...Show more
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Jan 10, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to intera...Show more
Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to interaction between Software Update and distribution scripts.Show less
1Apple
1Mac Os X Server
Apr 29, 2026
Nov 17, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-ma...Show more
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive.
1Apple
1Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DO...Show more
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (applicat...Show more
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (app...Show more
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.Show less
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie file.
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.