Vulnerabilities > Apple > MAC OS X Server > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-13 CVE-2010-1821 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
local
low complexity
apple CWE-20
7.2
2015-09-05 CVE-2015-5986 Improper Input Validation vulnerability in multiple products
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
network
isc apple CWE-20
7.1
2015-09-05 CVE-2015-5722 Improper Input Validation vulnerability in multiple products
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
network
low complexity
isc apple CWE-20
7.8
2014-07-01 CVE-2014-1371 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.
network
low complexity
apple CWE-119
7.5
2014-02-27 CVE-2014-1256 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
network
low complexity
apple CWE-119
7.5
2012-09-20 CVE-2012-3716 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.
network
low complexity
apple CWE-119
7.5
2012-09-20 CVE-2012-0650 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
network
low complexity
apple CWE-119
7.5
2012-05-11 CVE-2012-0662 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.
network
low complexity
apple CWE-189
7.5
2012-02-02 CVE-2011-3463 Improper Authentication vulnerability in Apple mac OS X and mac OS X Server
WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server or (2) a bound directory.
local
low complexity
apple CWE-287
7.2
2012-02-02 CVE-2011-3460 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PNG file.
network
low complexity
apple CWE-119
7.5