Skip to main content

Vendor archive

apple CVEs

Beta · best-effort

14,942 CVEs tagged to vendor apple2,405 Critical, 6,153 High, 5,653 Medium, 731 Low, 0 Unrated.

CVE-2003-0270

Published Jun 16, 2003

The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which c…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0378

Published Jun 16, 2003

The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the Authe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0420

Published Jun 13, 2003

Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0242

Published Jun 9, 2003

IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the pol…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0355

Published Jun 9, 2003

Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0171

Published May 5, 2003

DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0168

Published Apr 2, 2003

Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0055

Published Mar 7, 2003

Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0049

Published Mar 3, 2003

Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0088

Published Mar 3, 2003

TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1898

Published Dec 31, 2002

Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2326

Published Dec 31, 2002

The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1366

Published Dec 26, 2002

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1367

Published Dec 26, 2002

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1368

Published Dec 26, 2002

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative argum…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1369

Published Dec 26, 2002

jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attacker…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 14,876-14,900 of 14,942 CVEsPage 596 of 598