← Back

Mac Os X Server

mac_os_x_server

Vendor: Apple • 655 CVEs

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (me...Show more
The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted program.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via crafted DNS data.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password f...Show more
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and applic...Show more
CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via a long URL.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via...Show more
Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection...Show more
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by...Show more
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.
1Apple
3Iphone Os
Mac Os XMac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sit...Show more
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or...Show more
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAutho...Show more
Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended bro...Show more
The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody account.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.6 LOW· v2
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http serv...Show more
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.