Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2003-03-07 CVE-2003-0054 Unspecified vulnerability in Apple products
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
network
low complexity
apple
7.5
2003-03-07 CVE-2003-0053 Cross-Site Scripting vulnerability in Apple products
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.
network
apple
4.3
2003-03-07 CVE-2003-0052 Unspecified vulnerability in Apple products
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
network
low complexity
apple
5.0
2003-03-07 CVE-2003-0051 Remote Path Disclosure vulnerability in Apple products
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
network
low complexity
apple
5.0
2003-03-07 CVE-2003-0050 Unspecified vulnerability in Apple products
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
network
low complexity
apple
7.5
2003-03-03 CVE-2003-0088 Privilege Escalation vulnerability in Apple MacOS Classic TruBlueEnvironment Environment Variable
TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.
local
low complexity
apple
7.2
2003-03-03 CVE-2003-0049 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
network
low complexity
apple
7.5
2002-12-31 CVE-2002-2373 Configuration vulnerability in Apple TCP IP Configuration Utility 12640
The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.
network
low complexity
apple CWE-16
7.5
2002-12-31 CVE-2002-2326 Cryptographic Issues vulnerability in Apple mac OS X
The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.
network
low complexity
apple CWE-310
5.0
2002-12-26 CVE-2002-1383 Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
network
low complexity
easy-software-products apple
critical
10.0