Mac Os X Server

Vendor:

First CVE: Nov 4, 2002 · Active for 23 years

817
Total CVEs
More Total CVEs than 100% of tracked products
51.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mac Os X Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2002
23 years ago
Most Recent CVE
Apr 13, 2017
3,389 days ago

CVE Severity & Scoring

Mac Os X Server817 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local4 (0.5%)
Network32 (3.9%)
Unknown781 (95.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (4.2%)
High2 (0.2%)
Unknown781 (95.6%)
User Interaction
None31 (3.8%)
Unknown781 (95.6%)
Required5 (0.6%)
Privileges Required
Low4 (0.5%)
High0 (0.0%)
None32 (3.9%)
Unknown781 (95.6%)

Top CVEs

Signals from CVEs in this product scope (817 CVEs).

817 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug
Aug 27, 20039.881NOYES
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an
Jul 16, 20079.878NOYES
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Oct 6, 200310.073NOYES
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a
Jul 21, 20118.872NOYES
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.
Oct 14, 20116.870NOYES
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG
Jun 30, 20109.867NOYES
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown
Feb 16, 20126.864NONO
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading
Feb 22, 20065.162NOYES
The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to
Aug 5, 20065.160NOYES
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User
Jul 7, 20045.159NOYES

Exploit Exposure

Signals from CVEs in this product scope (817 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
7 CVEs
0.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
58 CVEs
7.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (817 CVEs).

Media Mentions

Signals from CVEs in this product scope (817 CVEs).

Top CNAs Publishing CVEs For Mac Os X Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.344.713.2%00
5.0.214.38.6%00
5.0.1527.529.9%00
10.7.5186.22.0%00
10.7.4176.22.0%00
10.7.3225.91.9%00
10.7.2356.01.9%00
10.7.1545.92.0%00
10.7.0665.82.0%00
10.6.8356.04.1%00
10.6.7515.92.4%01
10.6.6575.92.4%01
10.6.5715.92.3%03
10.6.41116.12.7%05
10.6.31236.02.7%05
10.6.21426.12.9%07
10.6.11626.22.7%07
10.6.01596.22.7%07
10.6115.31.9%01
10.5.81306.22.6%04