Apple Security Advisories · December 2002 — Apple Security Advisories
16 advisories 16 CVEs

Apple-vendor CVEs for 2002-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2002-1368

OtherEPSS <= 49%CRITICAL2002-12-20

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative ...

CVEs:CVE-2002-1368

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1383

OtherEPSS <= 49%HIGH2002-12-20

Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, ...

CVEs:CVE-2002-1383

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1369

OtherEPSS <= 49%HIGH2002-12-26

jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVEs:CVE-2002-1369

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1347

OtherEPSS <= 49%CRITICAL2002-12-11

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped duri...

CVEs:CVE-2002-1347

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2002-1371

OtherEPSS <= 49%CRITICAL2002-12-26

filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.

CVEs:CVE-2002-1371

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1367

OtherEPSS <= 49%HIGH2002-12-26

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for ...

CVEs:CVE-2002-1367

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1898

macOSEPSS <= 49%CRITICAL2002-12-31

Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.

CVEs:CVE-2002-1898

Affected products

ProductStatusVendorPackageEcosystem
terminal affected apple
Upstream advisory

CVE-2002-1372

OtherEPSS <= 49%CRITICAL2002-12-26

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors...

CVEs:CVE-2002-1372

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
mac_os_x affected apple
Upstream advisory

CVE-2002-1267

macOSEPSS <= 49%HIGH2002-12-11

Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing Web Administration is Remotely Accessible."

CVEs:CVE-2002-1267

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-2373

OtherEPSS <= 49%HIGH2002-12-31

The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.

CVEs:CVE-2002-2373

Affected products

ProductStatusVendorPackageEcosystem
tcp_ip_configuration_utility affected apple
Upstream advisory

CVE-2002-2326

macOSEPSS <= 49%MEDIUM2002-12-31

The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network tra...

CVEs:CVE-2002-2326

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1366

OtherEPSS <= 49%MEDIUM2002-12-26

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.

CVEs:CVE-2002-1366

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1270

macOSEPSS <= 49%LOW2002-12-11

Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call.

CVEs:CVE-2002-1270

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1266

macOSEPSS <= 49%MEDIUM2002-12-11

Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."

CVEs:CVE-2002-1266

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1268

macOSEPSS <= 49%MEDIUM2002-12-11

Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."

CVEs:CVE-2002-1268

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2002-1269

macOSEPSS <= 49%MEDIUM2002-12-03

Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.

CVEs:CVE-2002-1269

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.