Apple Security Advisories · May 2003 — Apple Security Advisories
3 advisories 3 CVEs

Apple-vendor CVEs for 2003-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2003-0270

OtherActive exploitation (sightings)HIGH2003-05-12

The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing ...

CVEs:CVE-2003-0270

Affected products

ProductStatusVendorPackageEcosystem
802.11n affected apple — —
Upstream advisory

CVE-2003-0242

macOSEPSS <= 49%HIGH2003-05-17

IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.

CVEs:CVE-2003-0242

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0355

SafariEPSS <= 49%MEDIUM2003-05-30

Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.

CVEs:CVE-2003-0355

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.