Apple Security Advisories · December 2003 — Apple Security Advisories
4 advisories 4 CVEs

Apple-vendor CVEs for 2003-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2003-1414

OtherEPSS <= 49%HIGH2003-12-31

Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.

CVEs:CVE-2003-1414

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple — —
quicktime_streaming_server affected apple — —
Upstream advisory

CVE-2003-1005

macOSEPSS <= 49%HIGH2003-12-31

The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.

CVEs:CVE-2003-1005

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2003-0975

macOSEPSS <= 49%MEDIUM2003-12-10

Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

CVEs:CVE-2003-0975

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
safari affected apple — —
Upstream advisory

CVE-2003-1413

OtherEPSS <= 49%MEDIUM2003-12-31

parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

CVEs:CVE-2003-1413

Affected products

ProductStatusVendorPackageEcosystem
darwin_streaming_server affected apple — —
quicktime_streaming_server affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.