6.4

CVE-2011-0212

servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApplemacOS X Server Version10.6.0
ApplemacOS X Server Version10.6.1
ApplemacOS X Server Version10.6.2
ApplemacOS X Server Version10.6.3
ApplemacOS X Server Version10.6.4
ApplemacOS X Server Version10.6.5
ApplemacOS X Server Version10.6.6
ApplemacOS X Server Version10.6.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.677
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P