← Vulnerability feed

Vulnerability record · CVE-2003-1413 · published 31 December 2003

CVE-2003-1413: Apple darwin streaming server path traversal vulnerability

Apple · Darwin Streaming Server

parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

4.3 CVSS 2.0 Medium EPSS 1.2% · top 32.8% CWE-22 · Path traversal
4.3CVSS 2.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-1413 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-0748Apple darwin streaming server vulnerabilityHeap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbit…EPSS 6.5%10.0CVE-2007-0749Apple darwin streaming server vulnerabilityMultiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server befor…EPSS 6.5%10.0CVE-2003-0421Apple darwin streaming server vulnerabilityApple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. …EPSS 2.9%10.0CVE-2003-0426Apple darwin streaming server vulnerabilityThe installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allow…EPSS 3.4%10.0CVE-2003-0502Apple darwin streaming server vulnerabilityApple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence foll…EPSS 3.4%7.5CVE-2004-1083Apple darwin streaming server vulnerabilityApache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a c…EPSS 1.9%7.5CVE-2004-1086Apple darwin streaming server vulnerabilityBuffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.EPSS 3.4%7.5CVE-2004-1088Apple darwin streaming server vulnerabilityPostfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authenticatio…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2003-1413), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.