← Back

Mac Os X Server

mac_os_x_server

Vendor: Apple • 655 CVEs

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Dec 1, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."
3Apple
FreebsdOpenbsd
4Freebsd
Mac Os XMac Os X Server+1 more
Apr 16, 2026
Nov 17, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via...Show more
The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Nov 3, 2003
N/A· v4
N/A· v3
2.1 LOW· v2
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have l...Show more
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Nov 3, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."
11Apple
CompaqFreebsd+8 more
18Advanced Message Server
AixFreebsd+15 more
Apr 16, 2026
Oct 6, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
8Apple
GentooHp+5 more
14Advanced Message Server
AixHp Ux+11 more
Apr 16, 2026
Oct 6, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
7Apple
FreebsdNetbsd+4 more
8Freebsd
Mac Os XMac Os X Server+5 more
Apr 16, 2026
Aug 27, 2003
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathname...Show more
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Aug 18, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buf...Show more
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.Show less
1Apple
1Mac Os X Server
Apr 16, 2026
Jun 13, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 5, 2003
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
May 5, 2003
N/A· v4
N/A· v3
7.2 HIGH· v2
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a...Show more
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 16, 2026
Mar 3, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
2Apple
Cyrusimap
3Cyrus Sasl
Mac Os XMac Os X Server
Apr 16, 2026
Dec 18, 2002
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) charact...Show more
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.Show less
3Apple
GnuSgi
4Glibc
IrixMac Os X+1 more
Apr 16, 2026
Nov 12, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
6Apple
FreebsdFrees Wan+3 more
12Bluefire Ix1035 Router
FreebsdFrees Wan+9 more
Apr 16, 2026
Nov 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsu...Show more
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.Show less