CVE-2003-0502
published 2003-08-27CVE-2003-0502: Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an…
PriorityP425critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.43%
87.6th percentile
Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | darwin_streaming_server | <= 4.1.3g | — |
| apple | darwin_streaming_server | <= 5.5 | — |
| apple | darwin_streaming_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9g7g-grc6-f65g: Apple Darwin Streaming Server 5
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2005-2195 [CRITICAL] GHSA-9g7g-grc6-f65g: Apple Darwin Streaming Server 5
Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.
GHSA
GHSA-7854-5v42-f557: Apple QuickTime / Darwin Streaming Server before 4
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2003-0502 [CRITICAL] GHSA-7854-5v42-f557: Apple QuickTime / Darwin Streaming Server before 4
Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.
GHSA
GHSA-6v6f-c78w-p95p: Apple QuickTime / Darwin Streaming Server before 4
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2003-0421 [CRITICAL] GHSA-6v6f-c78w-p95p: Apple QuickTime / Darwin Streaming Server before 4
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.
No detection rules found.
No writeups or analysis indexed.
2003-08-27
Published