Vulnerabilities > Apple > MAC OS X > 10.3

DATE CVE VULNERABILITY TITLE RISK
2005-03-21 CVE-2005-0713 Unspecified vulnerability in Apple mac OS X and mac OS X Server
The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.
local
low complexity
apple
4.6
2005-01-27 CVE-2004-0927 Multiple Security vulnerability in Apple Mac OS X
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
network
low complexity
easy-software-products apple
5.0
2005-01-27 CVE-2004-0926 Multiple Security vulnerability in Apple Mac OS X
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
network
low complexity
easy-software-products apple
critical
10.0
2005-01-27 CVE-2004-0925 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
network
low complexity
apple
5.0
2005-01-27 CVE-2004-0924 Multiple Security vulnerability in Apple Mac OS X
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
network
low complexity
easy-software-products apple
5.0
2005-01-27 CVE-2004-0923 Local Password Disclosure vulnerability in CUPS Error_Log
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.
local
low complexity
easy-software-products apple
2.1
2005-01-27 CVE-2004-0922 Multiple Security vulnerability in Apple Mac OS X
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
network
low complexity
apple
5.0
2005-01-27 CVE-2004-0921 Multiple Security vulnerability in Apple Mac OS X
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
network
low complexity
apple
7.5
2005-01-27 CVE-2004-0886 Buffer Overflow vulnerability in LibTIFF
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
5.0
2005-01-10 CVE-2004-1123 Unspecified vulnerability in Apple products
Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
network
low complexity
apple
5.0