Vulnerabilities > Apple > High

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1091 Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.
network
low complexity
apple
7.5
2003-11-17 CVE-2001-1411 Local Security vulnerability in Apple mac OS X 10.4.9
Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.
local
low complexity
apple
7.2
2003-11-03 CVE-2003-0881 Remote Security vulnerability in Mac OS X
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.
network
low complexity
apple
7.5
2003-11-03 CVE-2003-0871 Apple Quicktime Java vulnerability in Apple Mac OS X 10.3
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."
network
low complexity
apple
7.5
2003-10-06 CVE-2003-0681 Buffer Overflow vulnerability in Sendmail Ruleset Parsing
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
network
low complexity
sendmail apple gentoo hp ibm netbsd openbsd turbolinux
7.5
2003-06-16 CVE-2003-0378 Unspecified vulnerability in Apple mac OS X
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.
network
low complexity
apple
7.5
2003-06-16 CVE-2003-0370 Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
network
low complexity
apple kde redhat turbolinux
7.5
2003-06-16 CVE-2003-0270 Unspecified vulnerability in Apple 802.11N 7.3.1
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.
network
high complexity
apple
7.6
2003-06-09 CVE-2003-0242 Unspecified vulnerability in Apple mac OS X
IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.
network
low complexity
apple
7.5
2003-05-05 CVE-2003-0171 Unspecified vulnerability in Apple mac OS X and mac OS X Server
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
local
low complexity
apple
7.2