Mac Os X Server
Vendor:
First CVE: Nov 4, 2002 · Active for 23 years
817
Total CVEs
More Total CVEs than 100% of tracked products
51.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mac Os X Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2002
23 years ago
Most Recent CVE
Apr 13, 2017
3,389 days ago
CVE Severity & Scoring
Mac Os X Server817 CVEs
53%
38%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (0.5%)
Network32 (3.9%)
Unknown781 (95.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (4.2%)
High2 (0.2%)
Unknown781 (95.6%)
User Interaction
None31 (3.8%)
Unknown781 (95.6%)
Required5 (0.6%)
Privileges Required
Low4 (0.5%)
High0 (0.0%)
None32 (3.9%)
Unknown781 (95.6%)
Top CVEs
Signals from CVEs in this product scope (817 CVEs).
817 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0466CRITICAL Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug | Aug 27, 2003 | 9.8 | 81 | NO | YES |
CVE-2007-3798CRITICAL Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an | Jul 16, 2007 | 9.8 | 78 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2011-1774HIGH WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a | Jul 21, 2011 | 8.8 | 72 | NO | YES |
CVE-2011-3230MEDIUM Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site. | Oct 14, 2011 | 6.8 | 70 | NO | YES |
CVE-2010-1205CRITICAL Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG | Jun 30, 2010 | 9.8 | 67 | NO | YES |
CVE-2011-3026MEDIUM Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown | Feb 16, 2012 | 6.8 | 64 | NO | NO |
CVE-2006-0848MEDIUM The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading | Feb 22, 2006 | 5.1 | 62 | NO | YES |
CVE-2006-0395MEDIUM The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to | Aug 5, 2006 | 5.1 | 60 | NO | YES |
CVE-2004-0430MEDIUM Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User | Jul 7, 2004 | 5.1 | 59 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (817 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
7 CVEs
0.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
58 CVEs
7.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (817 CVEs).
Media Mentions
Signals from CVEs in this product scope (817 CVEs).
Top CNAs Publishing CVEs For Mac Os X Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.3 | 4 | 4.7 | 13.2% | 0 | 0 |
| 5.0.2 | 1 | 4.3 | 8.6% | 0 | 0 |
| 5.0.15 | 2 | 7.5 | 29.9% | 0 | 0 |
| 10.7.5 | 18 | 6.2 | 2.0% | 0 | 0 |
| 10.7.4 | 17 | 6.2 | 2.0% | 0 | 0 |
| 10.7.3 | 22 | 5.9 | 1.9% | 0 | 0 |
| 10.7.2 | 35 | 6.0 | 1.9% | 0 | 0 |
| 10.7.1 | 54 | 5.9 | 2.0% | 0 | 0 |
| 10.7.0 | 66 | 5.8 | 2.0% | 0 | 0 |
| 10.6.8 | 35 | 6.0 | 4.1% | 0 | 0 |
| 10.6.7 | 51 | 5.9 | 2.4% | 0 | 1 |
| 10.6.6 | 57 | 5.9 | 2.4% | 0 | 1 |
| 10.6.5 | 71 | 5.9 | 2.3% | 0 | 3 |
| 10.6.4 | 111 | 6.1 | 2.7% | 0 | 5 |
| 10.6.3 | 123 | 6.0 | 2.7% | 0 | 5 |
| 10.6.2 | 142 | 6.1 | 2.9% | 0 | 7 |
| 10.6.1 | 162 | 6.2 | 2.7% | 0 | 7 |
| 10.6.0 | 159 | 6.2 | 2.7% | 0 | 7 |
| 10.6 | 11 | 5.3 | 1.9% | 0 | 1 |
| 10.5.8 | 130 | 6.2 | 2.6% | 0 | 4 |