Apple Security Advisories · July 2003 — Apple Security Advisories
11 advisories 11 CVEs

Apple-vendor CVEs for 2003-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2004-0112

OtherEPSS <= 49%HIGH2003-07-18

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a cr...

CVEs:CVE-2004-0112

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2004-0079

OtherEPSS <= 49%HIGH2003-07-18

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVEs:CVE-2004-0079

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2004-0081

OtherEPSS <= 49%HIGH2003-07-18

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVEs:CVE-2004-0081

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2003-0426

OtherEPSS <= 49%HIGH2003-07-25

The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.

CVEs:CVE-2003-0426

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple
Upstream advisory

CVE-2003-0502

OtherEPSS <= 49%HIGH2003-07-25

Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than...

CVEs:CVE-2003-0502

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple
Upstream advisory

CVE-2003-0421

OtherEPSS <= 49%HIGH2003-07-25

Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.

CVEs:CVE-2003-0421

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple
Upstream advisory

CVE-2003-0423

OtherEPSS <= 49%CRITICAL2003-07-25

parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.

CVEs:CVE-2003-0423

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple
Upstream advisory

CVE-2003-0422

OtherEPSS <= 49%HIGH2003-07-25

Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.

CVEs:CVE-2003-0422

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple
Upstream advisory

CVE-2003-0425

OtherEPSS <= 49%HIGH2003-07-25

Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.

CVEs:CVE-2003-0425

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple
Upstream advisory

CVE-2003-0424

OtherEPSS <= 49%CRITICAL2003-07-25

Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.

CVEs:CVE-2003-0424

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple
Upstream advisory

CVE-2003-0518

macOSEPSS <= 49%HIGH2003-07-10

The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.

CVEs:CVE-2003-0518

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.