Apple Security Advisories · December 2001 — Apple Security Advisories
6 advisories 6 CVEs

Apple-vendor CVEs for 2001-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2001-1531

OtherEPSS <= 49%CRITICAL2001-12-31

Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename.

CVEs:CVE-2001-1531

Affected products

ProductStatusVendorPackageEcosystem
claris_emailer affected apple — —
Upstream advisory

CVE-2001-0720

macOSEPSS <= 49%CRITICAL2001-12-06

Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.

CVEs:CVE-2001-0720

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2001-1480

OtherEPSS <= 49%HIGH2001-12-31

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

CVEs:CVE-2001-1480

Affected products

ProductStatusVendorPackageEcosystem
mac_os_runtime_for_java affected apple — —
Upstream advisory

CVE-2001-1575

OtherEPSS <= 49%CRITICAL2001-12-31

Apple Personal Web Sharing (PWS) 1.1, 1.5, and 1.5.5, when Web Sharing authentication is enabled, allows remote attackers to cause a denial of service via a long password, possibly due to a buffer overflow.

CVEs:CVE-2001-1575

Affected products

ProductStatusVendorPackageEcosystem
personal_web_sharing affected apple — —
Upstream advisory

CVE-2001-1565

macOSEPSS <= 49%LOW2001-12-31

Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.

CVEs:CVE-2001-1565

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2001-0806

macOSEPSS <= 49%LOW2001-12-06

Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.

CVEs:CVE-2001-0806

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.