Apple Security Advisories · October 2003 — Apple Security Advisories
11 advisories 11 CVEs

Apple-vendor CVEs for 2003-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2003-0871

macOSEPSS <= 49%HIGH2003-10-30

Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."

CVEs:CVE-2003-0871

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2003-0881

macOSEPSS <= 49%HIGH2003-10-30

Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.

CVEs:CVE-2003-0881

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0882

macOSEPSS <= 49%MEDIUM2003-10-30

Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.

CVEs:CVE-2003-0882

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2001-1412

macOSEPSS <= 49%LOW2003-10-25

nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.

CVEs:CVE-2001-1412

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0895

macOSEPSS <= 49%HIGH2003-10-30

Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).

CVEs:CVE-2003-0895

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2001-1411

macOSEPSS <= 49%HIGH2003-10-25

Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

CVEs:CVE-2001-1411

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0876

macOSEPSS <= 49%LOW2003-10-30

Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than...

CVEs:CVE-2003-0876

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2003-0877

macOSEPSS <= 49%MEDIUM2003-10-30

Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.

CVEs:CVE-2003-0877

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0880

macOSEPSS <= 49%MEDIUM2003-10-30

Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.

CVEs:CVE-2003-0880

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0883

macOSEPSS <= 49%MEDIUM2003-10-30

The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.

CVEs:CVE-2003-0883

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2003-0878

macOSEPSS <= 49%MEDIUM2003-10-30

slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.

CVEs:CVE-2003-0878

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.