Apple Security Advisories · March 2009 — Apple Security Advisories
5 advisories 5 CVEs

Apple-vendor CVEs for 2009-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-1042

macOSEPSS <= 49%HIGH2009-03-23

Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

CVEs:CVE-2009-1042

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-1060

macOSEPSS <= 49%HIGH2009-03-24

Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Charlie Miller during a PWN2OWN competition at CanSecWest 2009.

CVEs:CVE-2009-1060

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0146

OtherEPSS <= 49%CRITICAL2009-03-18

Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2)...

CVEs:CVE-2009-0146

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2009-0016

OtherEPSS <= 49%HIGH2009-03-14

Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.

CVEs:CVE-2009-0016

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2009-0143

OtherEPSS <= 49%MEDIUM2009-03-14

Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.

CVEs:CVE-2009-0143

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.