Os X Server
Vendor:
First CVE: Sep 19, 2013 · Active for 12 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Os X Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2013
12 years ago
Most Recent CVE
Sep 25, 2016
3,590 days ago
CVE Severity & Scoring
Os X Server11 CVEs
18%
55%
18%
9%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (27.3%)
Unknown8 (72.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (27.3%)
High0 (0.0%)
Unknown8 (72.7%)
User Interaction
None2 (18.2%)
Unknown8 (72.7%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (27.3%)
Unknown8 (72.7%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4694CRITICAL The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrus | Sep 25, 2016 | 9.1 | 28 | NO | NO |
CVE-2016-4754HIGH ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. | Sep 25, 2016 | 7.5 | 24 | NO | NO |
CVE-2013-5143MEDIUM The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified circumstances, which might allow man-in-the-middle attackers to | Oct 24, 2013 | 6.8 | 22 | NO | NO |
CVE-2014-4424HIGH SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via | Sep 19, 2014 | 7.5 | 20 | NO | NO |
CVE-2014-3583MEDIUM The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer ove | Dec 15, 2014 | 5.0 | 19 | NO | NO |
CVE-2014-4406MEDIUM Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via u | Sep 19, 2014 | 6.1 | 18 | NO | NO |
CVE-2015-1151MEDIUM Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client. | Apr 28, 2015 | 5.0 | 16 | NO | NO |
CVE-2015-1150MEDIUM The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration files, which allows remote attackers to bypass network-access restrictions by sen | Apr 28, 2015 | 5.0 | 15 | NO | NO |
CVE-2013-1034MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecifi | Sep 19, 2013 | 4.3 | 14 | NO | NO |
Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file after a (1) profile setup or (2) profile edit occurs. | Oct 18, 2014 | 1.9 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Os X Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.3 | 1 | 5.0 | 10.8% | 0 | 0 |
| 3.1.2 | 1 | 7.5 | 2.4% | 0 | 0 |
| 3.1.1 | 2 | 6.8 | 1.9% | 0 | 0 |
| 3.1 | 2 | 6.8 | 1.9% | 0 | 0 |
| 3.0.3 | 2 | 6.8 | 1.9% | 0 | 0 |
| 3.0.2 | 2 | 6.8 | 1.9% | 0 | 0 |
| 3.0.1 | 2 | 6.8 | 1.9% | 0 | 0 |
| 3.0 | 2 | 6.8 | 1.9% | 0 | 0 |
| 2.2.2 | 1 | 6.1 | 1.4% | 0 | 0 |
| 2.2.1 | 3 | 6.8 | 1.4% | 0 | 0 |
| 2.2.0 | 1 | 4.3 | 2.0% | 0 | 0 |
| 2.2 | 3 | 6.8 | 1.4% | 0 | 0 |
| 2.1.1 | 4 | 6.2 | 1.6% | 0 | 0 |
| 2.1 | 4 | 6.2 | 1.6% | 0 | 0 |
| 2.0 | 4 | 6.2 | 1.6% | 0 | 0 |