Vulnerabilities > Apple > MAC OS X Server > High

DATE CVE VULNERABILITY TITLE RISK
2005-12-22 CVE-2005-4504 Remote Denial of Service vulnerability in Apple Mac OS X KHTMLParser
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.
network
low complexity
apple
7.8
2005-12-14 CVE-2005-4217 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X Server 10.3.9
Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.
network
low complexity
apple CWE-264
7.5
2005-12-01 CVE-2005-3705 Multiple vulnerability in RETIRED: Apple Mac OS X Security Update 2005-009
Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers to execute arbitrary code via unknown attack vectors.
network
low complexity
apple
7.5
2005-12-01 CVE-2005-3701 Multiple vulnerability in Apple mac OS X Server 10.3.9/10.4.3
Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users to gain privileges via unknown attack vectors.
local
low complexity
apple
7.2
2005-12-01 CVE-2005-2757 Multiple vulnerability in RETIRED: Apple Mac OS X Security Update 2005-009
Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving "validation of URLs."
network
low complexity
apple
7.5
2005-10-26 CVE-2005-2743 Unspecified vulnerability in Apple mac OS X, mac OS X Server and Quicktime
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
network
low complexity
apple
7.5
2005-10-26 CVE-2005-2741 Permissions, Privileges, and Access Controls vulnerability in multiple products
Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators.
local
low complexity
apple perry-kiehtreiber CWE-264
7.2
2005-10-25 CVE-2005-2747 Multiple vulnerability in Apple Mac OS X Security Update 2005-008
Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file.
network
low complexity
apple
7.5
2005-08-19 CVE-2005-2507 Unspecified vulnerability in Apple mac OS X Server 10.3.9/10.4.2
Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
network
low complexity
apple
7.5
2005-08-19 CVE-2005-2504 Unspecified vulnerability in Apple mac OS X and mac OS X Server
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.
local
low complexity
apple
7.2