← Back

Mac Os X Server

mac_os_x_server

Vendor: Apple • 655 CVEs

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jan 20, 2010
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Dec 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers to execute arbitrary code via an applet.
5Apple
CanonicalDebian+2 more
7Cups
Debian LinuxEnterprise Linux+4 more
Apr 23, 2026
Nov 20, 2009
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a de...Show more
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local users to overwrite arbitrary files in the context of a different user's privileges via unspecified vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account vi...Show more
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecif...Show more
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) Bluetooth keyboard via unspecified vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the UCCompareTextDefault API in International Components for Unicode in Apple Mac OS X 10.5.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application cras...Show more
Buffer overflow in the UCCompareTextDefault API in International Components for Unicode in Apple Mac OS X 10.5.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.Show less
1Apple
1Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hiera...Show more
Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a "CWD command line tool."Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any contents, and thereby execute arbitrary code, via crafted JavaScript, related to a "design issue."
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a c...Show more
Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.Show less
1Apple
1Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log do...Show more
Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a "log injection" issue.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk i...Show more
Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk image.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based...Show more
Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based buffer overflow.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attack...Show more
Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site s...Show more
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.Show less