Apple

macOS X Server

655 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which allows remote authenticated users to leverage this former membership to obtain a server connection vi...

  • EPSS 0.21%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java applet.

  • EPSS 0.38%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a cr...

  • EPSS 0.13%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive i...

  • EPSS 5.05%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPE...

  • EPSS 0.14%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.

  • EPSS 0.17%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions ...

  • EPSS 0.24%
  • Veröffentlicht 30.03.2010 18:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a craft...

  • EPSS 0.65%
  • Veröffentlicht 30.03.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified package.

  • EPSS 1.93%
  • Veröffentlicht 30.03.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.