Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2004-1081

Disclosure Date: December 02, 2004 (last updated February 22, 2025)
The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.
0
Attacker Value
Unknown

CVE-2004-0169

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.
0
Attacker Value
Unknown

CVE-2003-0421

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.
0
Attacker Value
Unknown

CVE-2003-0425

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.
0
Attacker Value
Unknown

CVE-2003-0426

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.
0
Attacker Value
Unknown

CVE-2003-0423

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.
0
Attacker Value
Unknown

CVE-2003-0424

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.
0
Attacker Value
Unknown

CVE-2003-0422

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.
0