← Back

Mac Os X Server

mac_os_x_server

Vendor: Apple • 655 CVEs

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 18, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 18, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 18, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 18, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Jul 7, 2004
N/A· v4
N/A· v3
7.6 HIGH· v2
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in th...Show more
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Jul 7, 2004
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request wit...Show more
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 3, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 29, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious...Show more
Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 29, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 29, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 29, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.
1Apple
1Mac Os X Server
Apr 16, 2026
Mar 29, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new ac...Show more
Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 15, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 15, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 15, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 15, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentia...Show more
Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
1Apple
3Mac Os X
Mac Os X ServerSafari
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.