Apple Security Advisories · December 2002 — Apple Security Advisories
16 advisories 16 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2002-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2002-1368

OtherExploitedVulnCheck KEV listedCRITICAL2002-12-20

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative ...

CVEs:CVE-2002-1368

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1383

OtherEPSS <= 49%HIGH2002-12-20

Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, ...

CVEs:CVE-2002-1383

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1369

OtherEPSS <= 49%HIGH2002-12-26

jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVEs:CVE-2002-1369

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1347

OtherEPSS <= 49%CRITICAL2002-12-11

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped duri...

CVEs:CVE-2002-1347

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2002-1371

OtherEPSS <= 49%CRITICAL2002-12-26

filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.

CVEs:CVE-2002-1371

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1367

OtherEPSS <= 49%HIGH2002-12-26

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for ...

CVEs:CVE-2002-1367

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1898

macOSEPSS <= 49%CRITICAL2002-12-31

Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.

CVEs:CVE-2002-1898

Affected products

ProductStatusVendorPackageEcosystem
terminal affected apple — —
Upstream advisory

CVE-2002-1372

OtherEPSS <= 49%CRITICAL2002-12-26

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors...

CVEs:CVE-2002-1372

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1267

macOSEPSS <= 49%HIGH2002-12-11

Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing Web Administration is Remotely Accessible."

CVEs:CVE-2002-1267

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-2373

OtherEPSS <= 49%HIGH2002-12-31

The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.

CVEs:CVE-2002-2373

Affected products

ProductStatusVendorPackageEcosystem
tcp_ip_configuration_utility affected apple — —
Upstream advisory

CVE-2002-2326

macOSEPSS <= 49%MEDIUM2002-12-31

The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network tra...

CVEs:CVE-2002-2326

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1366

OtherEPSS <= 49%MEDIUM2002-12-26

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.

CVEs:CVE-2002-1366

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1270

macOSEPSS <= 49%LOW2002-12-11

Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call.

CVEs:CVE-2002-1270

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1266

macOSEPSS <= 49%MEDIUM2002-12-11

Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."

CVEs:CVE-2002-1266

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1268

macOSEPSS <= 49%MEDIUM2002-12-11

Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."

CVEs:CVE-2002-1268

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2002-1269

macOSEPSS <= 49%MEDIUM2002-12-03

Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.

CVEs:CVE-2002-1269

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.