Vulnerabilities > Apple > MAC OS X Server > 5.0.3

DATE CVE VULNERABILITY TITLE RISK
2016-03-24 CVE-2016-1787 Information Exposure vulnerability in Apple mac OS X Server
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
network
low complexity
apple CWE-200
5.0
2016-03-24 CVE-2016-1777 Cryptographic Issues vulnerability in Apple mac OS X Server
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
network
low complexity
apple CWE-310
5.0
2016-03-24 CVE-2016-1776 Improper Access Control vulnerability in Apple mac OS X Server
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.
network
low complexity
apple CWE-284
5.0
2016-03-24 CVE-2016-1774 Improper Access Control vulnerability in Apple mac OS X Server
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.
network
low complexity
apple CWE-284
5.0
2015-10-23 CVE-2015-7031 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X Server 5.0.14/5.0.2/5.0.3
The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.
network
low complexity
apple CWE-264
5.0
2014-03-31 CVE-2014-0067 Permissions, Privileges, and Access Controls vulnerability in multiple products
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
local
low complexity
apple postgresql CWE-264
4.6
2013-06-05 CVE-2013-0984 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message.
network
apple CWE-119
critical
9.3
2012-09-20 CVE-2012-3723 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device.
local
low complexity
apple CWE-119
4.6
2012-09-20 CVE-2012-3722 Resource Management Errors vulnerability in Apple Iphone OS, mac OS X and mac OS X Server
The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
network
apple CWE-399
6.8
2012-09-20 CVE-2012-3719 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code via an e-mail message that triggers the loading of a third-party plugin.
network
apple CWE-20
6.8