← Back

Mac Os X Server

mac_os_x_server

Vendor: Apple • 655 CVEs

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Mar 13, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Mar 13, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory cor...Show more
Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Mar 13, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Feb 22, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image th...Show more
Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression. NOTE: this is a different issue than CVE-2006-3502 and CVE-2006-3503.Show less
3Apple
ClamavDebian
3Clamav
Debian LinuxMac Os X Server
Apr 23, 2026
Feb 16, 2007
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives...Show more
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.Show less
2Apple
Freebsd
3Freebsd
Mac Os XMac Os X Server
Apr 23, 2026
Jan 13, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a ne...Show more
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jan 9, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, whi...Show more
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Dec 20, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered b...Show more
QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered by other embedded QuickTime objects.Show less
1Apple
3Bomarchivehelper
Mac Os XMac Os X Server
Apr 23, 2026
Dec 7, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FA...Show more
Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the "iSec Partners FileP fuzzer".Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 27, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 27, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as...Show more
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 27, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 22, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which trigge...Show more
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 22, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity o...Show more
com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity of this issue has been disputed by a third party, who states that the impact is limited to a denial of service (kernel panic) due to a vm_fault call with a non-aligned address.Show less
3Apple
DebianOpenbsd
4Debian Linux
Mac Os XMac Os X Server+1 more
Apr 23, 2026
Sep 27, 2006
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead...Show more
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Sep 21, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless softw...Show more
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted frames.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Sep 21, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted fra...Show more
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Sep 21, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Sep 19, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
3Apple
CanonicalIsc
4Bind
Mac Os XMac Os X Server+1 more
Apr 16, 2026
Sep 6, 2006
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.