Apple Security Advisories · March 2003 — Apple Security Advisories
7 advisories 7 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2003-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2003-0050

OtherExploitedVulnCheck KEV listedCRITICAL2003-03-07

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

CVEs:CVE-2003-0050

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple — —
quicktime_streaming_server affected apple — —
Upstream advisory

CVE-2003-0055

OtherEPSS <= 49%CRITICAL2003-03-07

Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.

CVEs:CVE-2003-0055

Affected products

ProductStatusVendorPackageEcosystem
quicktime_darwin_mp3_broadcaster affected apple — —
Upstream advisory

CVE-2003-0054

OtherEPSS <= 49%HIGH2003-03-07

Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log ...

CVEs:CVE-2003-0054

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple — —
quicktime_streaming_server affected apple — —
Upstream advisory

CVE-2003-0051

OtherEPSS <= 49%MEDIUM2003-03-07

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.

CVEs:CVE-2003-0051

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple — —
quicktime_streaming_server affected apple — —
Upstream advisory

CVE-2003-0053

OtherEPSS <= 49%CRITICAL2003-03-07

Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into a...

CVEs:CVE-2003-0053

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple — —
quicktime_streaming_server affected apple — —
Upstream advisory

CVE-2003-0052

OtherEPSS <= 49%MEDIUM2003-03-07

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.

CVEs:CVE-2003-0052

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple — —
quicktime_streaming_server affected apple — —
Upstream advisory

CVE-2003-0088

macOSEPSS <= 49%HIGH2003-03-03

TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.

CVEs:CVE-2003-0088

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.