Advisories
OtherEPSS <= 49%HIGH2003-07-18
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a cr...
CVEs:CVE-2004-0112
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2003-07-18
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
CVEs:CVE-2004-0079
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2003-07-18
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
CVEs:CVE-2004-0081
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2003-07-25
The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.
CVEs:CVE-2003-0426
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| darwin_streaming_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2003-07-25
Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than...
CVEs:CVE-2003-0502
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| darwin_streaming_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2003-07-25
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.
CVEs:CVE-2003-0421
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| darwin_streaming_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2003-07-25
parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.
CVEs:CVE-2003-0423
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| darwin_streaming_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2003-07-25
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.
CVEs:CVE-2003-0422
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| darwin_streaming_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2003-07-25
Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.
CVEs:CVE-2003-0425
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| darwin_streaming_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2003-07-25
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.
CVEs:CVE-2003-0424
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| darwin_streaming_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2003-07-10
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.
CVEs:CVE-2003-0518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |