Os X Server

Vendor:

First CVE: Sep 19, 2013 · Active for 12 years

11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Os X Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2013
12 years ago
Most Recent CVE
Sep 25, 2016
3,590 days ago

CVE Severity & Scoring

Os X Server11 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (27.3%)
Unknown8 (72.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (27.3%)
High0 (0.0%)
Unknown8 (72.7%)
User Interaction
None2 (18.2%)
Unknown8 (72.7%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (27.3%)
Unknown8 (72.7%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrus
Sep 25, 20169.128NONO
ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Sep 25, 20167.524NONO
The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified circumstances, which might allow man-in-the-middle attackers to
Oct 24, 20136.822NONO
SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via
Sep 19, 20147.520NONO
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer ove
Dec 15, 20145.019NONO
Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via u
Sep 19, 20146.118NONO
Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client.
Apr 28, 20155.016NONO
The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration files, which allows remote attackers to bypass network-access restrictions by sen
Apr 28, 20155.015NONO
Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecifi
Sep 19, 20134.314NONO
Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file after a (1) profile setup or (2) profile edit occurs.
Oct 18, 20141.911NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Os X Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.315.010.8%00
3.1.217.52.4%00
3.1.126.81.9%00
3.126.81.9%00
3.0.326.81.9%00
3.0.226.81.9%00
3.0.126.81.9%00
3.026.81.9%00
2.2.216.11.4%00
2.2.136.81.4%00
2.2.014.32.0%00
2.236.81.4%00
2.1.146.21.6%00
2.146.21.6%00
2.046.21.6%00