VDB
CVE-2004-0922
CVE-2004-0922
PUBLISHED
CVSS 5 MEDIUM
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
EPSS 0.97% · 58.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
0.97%
58.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | mac_os_x_server | 10.2.4, 10.3.5, 10.3.4 |
| apple | quicktime | 5.0.2, 6.0, 6.5 |
| n/a | n/a | * |
| apple | mac_os_x | 10.2, 10.2.1, 10.2.3 |
Timeline
- Oct 28, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score