Skip to main content

Vendor/product archive

apple / os_x_server CVEs

Beta · best-effort

11 CVEs tagged to apple / os_x_server1 Critical, 2 High, 6 Medium, 2 Low, 0 Unrated.

CVE-2016-4754

Published Sep 25, 2016

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4694

Published Sep 25, 2016

The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untru…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1151

Published Apr 28, 2015

Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1150

Published Apr 28, 2015

The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration files, which allows remote attackers to bypass network-access restrictions by se…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4447

Published Oct 18, 2014

Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file after a (1) profile setup or (2) profile edit occurs.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4446

Published Oct 18, 2014

Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restric…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4424

Published Sep 19, 2014

SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4406

Published Sep 19, 2014

Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5143

Published Oct 24, 2013

The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified circumstances, which might allow man-in-the-middle attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1034

Published Sep 19, 2013

Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1