Vulnerabilities > Apple > MAC OS X Server > 10.2.2

DATE CVE VULNERABILITY TITLE RISK
2003-10-06 CVE-2003-0681 Buffer Overflow vulnerability in Sendmail Ruleset Parsing
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
network
low complexity
sendmail apple gentoo hp ibm netbsd openbsd turbolinux
7.5
2003-08-18 CVE-2003-0518 Unspecified vulnerability in Apple mac OS X and mac OS X Server
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.
local
low complexity
apple
4.6
2003-05-05 CVE-2003-0198 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
network
low complexity
apple
6.4
2003-05-05 CVE-2003-0171 Unspecified vulnerability in Apple mac OS X and mac OS X Server
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
local
low complexity
apple
7.2
2003-03-03 CVE-2003-0049 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
network
low complexity
apple
7.5
2002-12-18 CVE-2002-1347 Incorrect Calculation of Buffer Size vulnerability in multiple products
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
network
low complexity
cyrusimap apple CWE-131
critical
9.8