Vulnerabilities > Apple > MAC OS X Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2012-02-02 CVE-2011-3459 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rdrf atom in a movie file that triggers a buffer overflow.
network
apple CWE-189
6.8
2012-02-02 CVE-2011-3458 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 file.
network
apple CWE-264
6.8
2012-02-02 CVE-2011-3452 Information Exposure vulnerability in Apple mac OS X and mac OS X Server
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.
network
apple CWE-200
4.3
2012-02-02 CVE-2011-3450 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via a long URL.
network
apple CWE-399
6.8
2012-02-02 CVE-2011-3449 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.
network
apple CWE-399
6.8
2012-02-02 CVE-2011-3448 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
network
apple CWE-119
6.8
2012-02-02 CVE-2011-3447 Information Exposure vulnerability in Apple mac OS X and mac OS X Server
CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.
network
apple CWE-200
4.3
2012-02-02 CVE-2011-3444 Cryptographic Issues vulnerability in Apple mac OS X and mac OS X Server
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
network
apple CWE-310
4.3
2011-10-14 CVE-2011-3437 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
network
apple CWE-189
6.8
2011-10-14 CVE-2011-3436 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.
network
low complexity
apple CWE-264
6.5