Apple

macOS X Server

655 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 10.32%
  • Veröffentlicht 20.07.2015 23:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote...

  • EPSS 12.98%
  • Veröffentlicht 20.07.2015 23:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending...

  • EPSS 8.53%
  • Veröffentlicht 28.05.2015 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the auth...

  • EPSS 18.72%
  • Veröffentlicht 08.03.2015 02:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script ha...

  • EPSS 5.49%
  • Veröffentlicht 19.09.2014 10:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

  • EPSS 10.42%
  • Veröffentlicht 19.09.2014 10:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.

  • EPSS 1.85%
  • Veröffentlicht 01.07.2014 10:17:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archiv...

  • EPSS 0.79%
  • Veröffentlicht 01.07.2014 10:17:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a...

  • EPSS 0.21%
  • Veröffentlicht 23.04.2014 11:52:59
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restri...

Exploit
  • EPSS 75.57%
  • Veröffentlicht 15.04.2014 10:55:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...