VYPR
Unrated severityNVD Advisory· Published Apr 15, 2004· Updated Apr 16, 2026

CVE-2003-0514

CVE-2003-0514

Description

Apple Safari 1.x allows remote attackers to bypass cookie access restrictions using directory traversal sequences in URLs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Apple Safari 1.x allows remote attackers to bypass cookie access restrictions using directory traversal sequences in URLs.

Vulnerability

Apple Safari versions 1.x are vulnerable to a cookie path argument restriction bypass. The browser fails to properly sanitize encoded URI content, specifically allowing encoded directory traversal sequences like %2e%2e (dot dot) in URLs. This can trick Safari into sending cookies intended for a specific URL subset to an alternate, unintended path [1].

Exploitation

An attacker can craft a malicious URL containing encoded directory traversal sequences. When a user visits this URL in a vulnerable version of Apple Safari, the browser may send cookies associated with the target application to a different path on the same server. This bypasses the intended cookie access restrictions set by the web application [1].

Impact

Successful exploitation allows an attacker to access cookies that should be restricted to a specific URL subset. This could lead to unauthorized access to sensitive information or session hijacking if the cookies contain authentication tokens or other private data, depending on the application's logic and the data stored in the cookies [1].

Mitigation

No specific patched version or release date is available in the provided references. Users are advised to avoid visiting untrusted URLs. Further information on mitigation is not yet disclosed in the available references [1].

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Apple Inc./Safari3 versions
    cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*
    • (no CPE)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.