Apple Darwin Streaming Server vulnerabilities

27 known vulnerabilities affecting apple/darwin_streaming_server.

Total CVEs
27
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH5MEDIUM14LOW3

Vulnerabilities

Page 2 of 2
CVE-2003-0425MEDIUMCVSS 5.0v4.1.32003-08-27
CVE-2003-0425 [MEDIUM] CVE-2003-0425: Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.
nvd
CVE-2003-0423MEDIUMCVSS 5.0v4.1.32003-08-27
CVE-2003-0423 [MEDIUM] CVE-2003-0423: parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.
nvd
CVE-2003-0054HIGHCVSS 7.5v4.1.22003-03-07
CVE-2003-0054 [HIGH] CVE-2003-0054: Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remot Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
nvd
CVE-2003-0050HIGHCVSS 7.5PoCv4.1.22003-03-07
CVE-2003-0050 [HIGH] CVE-2003-0050: parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4 parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
nvd
CVE-2003-0052MEDIUMCVSS 5.0v4.1.22003-03-07
CVE-2003-0052 [MEDIUM] CVE-2003-0052: parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4 parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
nvd
CVE-2003-0051MEDIUMCVSS 5.0v4.1.22003-03-07
CVE-2003-0051 [MEDIUM] CVE-2003-0051: parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4 parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
nvd
CVE-2003-0053MEDIUMCVSS 4.3v4.1.22003-03-07
CVE-2003-0053 [MEDIUM] CVE-2003-0053: Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration S Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.
nvd