Apple
Apple MAC OS X Server: vulnerabilidades y CVE
Apple MAC OS X Server tiene 656 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE656
Últimos 12 meses0
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2010-1821 | Alta (7.8) | 0.30% | — | 13 abr 2017 | Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges. |
| CVE-2010-1816 | Alta (7.8) | 2.1% | — | 13 abr 2017 | Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image. |
| CVE-2016-1787 | Media (5.3) | 1.8% | — | 24 mar 2016 | Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors. |
| CVE-2016-1777 | Alta (7.5) | 2.0% | — | 24 mar 2016 | Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. |
| CVE-2016-1776 | Media (5.3) | 1.8% | — | 24 mar 2016 | Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request. |
| CVE-2016-1774 | Media (5.3) | 1.7% | — | 24 mar 2016 | The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in… |
| CVE-2015-7031 | Media (5) | 2.0% | — | 23 oct 2015 | The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors. |
| CVE-2015-5911 | Alta (10) | 2.0% | — | 18 sept 2015 | Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document. |
| CVE-2015-5986 | Alta (7.1) | 26% | — | 5 sept 2015 | openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response. |
| CVE-2015-5722 | Alta (7.8) | 34% | — | 5 sept 2015 | buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key… |
| CVE-2015-3185 | Media (4.3) | 16% | — | 20 jul 2015 | The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an… |
| CVE-2015-0253 | Media (5) | 13% | — | 20 jul 2015 | The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer… |
| CVE-2015-3165 | Media (4.3) | 8.5% | — | 28 may 2015 | Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL… |
| CVE-2015-0228 | Media (5) | 16% | — | 8 mar 2015 | The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket… |
| CVE-2014-4350 | Media (6.8) | 3.6% | — | 19 sept 2014 | Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file. |
| CVE-2014-1391 | Media (6.8) | 4.2% | — | 19 sept 2014 | QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding. |
| CVE-2014-1371 | Alta (7.5) | 1.9% | — | 1 jul 2014 | Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a… |
| CVE-2014-1370 | Media (6.8) | 2.2% | — | 1 jul 2014 | The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted… |
| CVE-2014-1296 | Media (4.3) | 1.9% | — | 23 abr 2014 | CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers… |
| CVE-2013-5704 | Media (5) | 53% | — | 15 abr 2014 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the… |
| CVE-2014-0067 | Media (4.6) | 0.48% | — | 31 mar 2014 | The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local… |
| CVE-2014-1270 | Media (6.8) | 2.2% | — | 27 feb 2014 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a… |
| CVE-2014-1269 | Media (6.8) | 2.2% | — | 27 feb 2014 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a… |
| CVE-2014-1268 | Media (6.8) | 1.9% | — | 27 feb 2014 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a… |
| CVE-2014-1265 | Media (4.6) | 0.34% | — | 27 feb 2014 | The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local users to bypass intended access restrictions by changing the current time on the system clock. |
| CVE-2014-1259 | Media (6.8) | 1.8% | — | 27 feb 2014 | Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename. |
| CVE-2014-1256 | Alta (7.5) | 1.3% | — | 27 feb 2014 | Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages. |
| CVE-2013-1024 | Media (6.8) | 2.9% | — | 5 jun 2013 | CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service… |
| CVE-2013-0990 | Media (4.9) | 1.2% | — | 5 jun 2013 | SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors. |
| CVE-2013-0984 | Alta (9.3) | 14% | — | 5 jun 2013 | Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message. |