Vulnerabilities > Apple > MAC OS X Server > 10.6.8

DATE CVE VULNERABILITY TITLE RISK
2012-05-11 CVE-2012-0675 Improper Authentication vulnerability in Apple mac OS X and mac OS X Server
Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.
network
apple CWE-287
4.3
2012-05-11 CVE-2012-0662 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.
network
low complexity
apple CWE-189
7.5
2012-05-11 CVE-2012-0660 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.
network
apple CWE-119
6.8
2012-05-11 CVE-2012-0659 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.
network
apple CWE-189
6.8
2012-05-11 CVE-2012-0658 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio sample tables in a movie file that is progressively downloaded.
network
apple CWE-119
6.8
2012-05-11 CVE-2012-0657 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.
local
low complexity
apple CWE-264
2.1
2012-05-11 CVE-2012-0655 Cryptographic Issues vulnerability in Apple mac OS X and mac OS X Server
libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by conducting a spoofing or network-sniffing attack during communication with a site that uses a short key.
network
low complexity
apple CWE-310
6.4
2012-05-11 CVE-2012-0654 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.
network
apple CWE-119
6.8
2012-05-11 CVE-2012-0651 Information Exposure vulnerability in Apple mac OS X and mac OS X Server
The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a crafted message.
network
low complexity
apple CWE-200
5.0
2012-05-11 CVE-2012-0649 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors involving a temporary file.
local
apple CWE-362
6.9