CVE Vulnerabilities

CVE-2002-2326

Published: Dec 31, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.

Affected Software

NameVendorStart VersionEnd Version
Mac_os_xApple10.0 (including)10.0 (including)
Mac_os_xApple10.0.1 (including)10.0.1 (including)
Mac_os_xApple10.0.2 (including)10.0.2 (including)
Mac_os_xApple10.0.3 (including)10.0.3 (including)
Mac_os_xApple10.0.4 (including)10.0.4 (including)
Mac_os_xApple10.1 (including)10.1 (including)
Mac_os_xApple10.1.1 (including)10.1.1 (including)
Mac_os_xApple10.1.2 (including)10.1.2 (including)
Mac_os_xApple10.1.3 (including)10.1.3 (including)
Mac_os_xApple10.1.4 (including)10.1.4 (including)
Mac_os_xApple10.1.5 (including)10.1.5 (including)

References