Apple Security Advisories · April 2003 — Apple Security Advisories
4 advisories 4 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2003-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2003-0201

OtherExploitedVulnCheck KEV listedHIGH2003-04-15

Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.

CVEs:CVE-2003-0201

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0168

OtherEPSS <= 49%CRITICAL2003-04-01

Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.

CVEs:CVE-2003-0168

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple — —
Upstream advisory

CVE-2003-0198

macOSEPSS <= 49%MEDIUM2003-04-15

Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.

CVEs:CVE-2003-0198

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2003-0171

macOSEPSS <= 49%HIGH2003-04-15

DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.

CVEs:CVE-2003-0171

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.