Apple Security Advisories · June 2010 — Apple Security Advisories
83 advisories 83 CVEs

Apple-vendor CVEs for 2010-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-1205

OtherWeaponized exploitCRITICAL2010-06-25

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVEs:CVE-2010-1205

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
mac_os_x_server affected apple
safari affected apple
Upstream advisory

CVE-2010-1759

macOSWeaponized exploitHIGH2010-06-08

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1759

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1411

macOSPoC exploitCRITICAL2010-06-11

Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause ...

CVEs:CVE-2010-1411

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1749

macOSPoC exploitHIGH2010-06-08

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1749

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1769

iOSPoC exploitHIGH2010-06-17

WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (applic...

CVEs:CVE-2010-1769

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2010-1412

macOSPoC exploitHIGH2010-06-08

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1412

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1419

macOSPoC exploitHIGH2010-06-08

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application cras...

CVEs:CVE-2010-1419

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1761

macOSPoC exploitHIGH2010-06-08

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1761

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1774

macOSPoC exploitHIGH2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses out-of-bounds memory during processing of HTML tables, which allows remote attackers to execute arbitrary code or cause a denial of s...

CVEs:CVE-2010-1774

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1752

iOSPoC exploitCRITICAL2010-06-22

Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to URL handling.

CVEs:CVE-2010-1752

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1408

macOSPoC exploitMEDIUM2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to bypass intended restrictions on outbound connections to "non-default TCP ports" via a crafted port number, related ...

CVEs:CVE-2010-1408

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1409

macOSPoC exploitMEDIUM2010-06-08

Incomplete blacklist vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to trigger disclosure of data over IRC via vectors involving an IRC service port.

CVEs:CVE-2010-1409

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1762

macOSPoC exploitCRITICAL2010-06-08

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML in a TEX...

CVEs:CVE-2010-1762

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1753

iOSPoC exploitCRITICAL2010-06-22

ImageIO in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG image.

CVEs:CVE-2010-1753

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1763

SafariPoC exploitHIGH2010-06-17

Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769.

CVEs:CVE-2010-1763

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2010-2249

OtherPoC exploitHIGH2010-06-25

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVEs:CVE-2010-2249

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2010-1413

macOSPoC exploitHIGH2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in unspecified circumstances, which allows man-in-the-middle attackers to obtain sensitive information via...

CVEs:CVE-2010-1413

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1751

iOSPoC exploitMEDIUM2010-06-22

Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not prevent photo-library access, which might allow remote attackers to obtain location information via unspecified vectors.

CVEs:CVE-2010-1751

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1756

iOSPoC exploitMEDIUM2010-06-22

The Settings application in Apple iOS before 4 on the iPhone and iPod touch does not properly report the wireless network that is in use, which might make it easier for remote attackers to trick users into communicating over an unintended network.

CVEs:CVE-2010-1756

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1755

iOSPoC exploitMEDIUM2010-06-22

Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the Accept Cookies preference, which makes it easier for remote web servers to track users via a cookie.

CVEs:CVE-2010-1755

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1754

iOSPoC exploitMEDIUM2010-06-22

Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote Lock operations through MobileMe, which allows physically proximate attackers to bypass intended passcod...

CVEs:CVE-2010-1754

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1775

iOSPoC exploitLOW2010-06-22

Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving...

CVEs:CVE-2010-1775

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1396

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1396

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1397

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1397

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1401

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause ...

CVEs:CVE-2010-1401

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1402

macOSEPSS <= 49%HIGH2010-06-07

Double free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors re...

CVEs:CVE-2010-1402

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1403

macOSEPSS <= 49%HIGH2010-06-07

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during the handling of a use element in an SVG document, which allows remote attackers to execute arbitrary code...

CVEs:CVE-2010-1403

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1404

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG ...

CVEs:CVE-2010-1404

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1398

macOSEPSS <= 49%HIGH2010-06-07

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly perform ordered list insertions, which allows remote attackers to execute arbitrary code or cause a denial of service (memor...

CVEs:CVE-2010-1398

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1410

macOSEPSS <= 49%HIGH2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an SVG document w...

CVEs:CVE-2010-1410

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-1783

OtherEPSS <= 49%HIGH2010-06-02

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory ...

CVEs:CVE-2011-1783

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2010-1399

macOSEPSS <= 49%HIGH2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during a selection change on a form input element, which allows remote attackers to execute arbitrary code or ca...

CVEs:CVE-2010-1399

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1400

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1400

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1405

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML...

CVEs:CVE-2010-1405

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1414

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1414

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1758

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1758

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1392

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1392

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1415

macOSEPSS <= 49%HIGH2010-06-07

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle libxml contexts, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) v...

CVEs:CVE-2010-1415

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1417

macOSEPSS <= 49%HIGH2010-06-07

The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...

CVEs:CVE-2010-1417

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1748

macOSEPSS <= 49%CRITICAL2010-06-15

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) charac...

CVEs:CVE-2010-1748

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2010-1771

macOSEPSS <= 49%HIGH2010-06-07

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors...

CVEs:CVE-2010-1771

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1387

iOSEPSS <= 49%HIGH2010-06-17

Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via ...

CVEs:CVE-2010-1387

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2010-1385

macOSEPSS <= 49%HIGH2010-06-08

Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF doc...

CVEs:CVE-2010-1385

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1750

SafariEPSS <= 49%HIGH2010-06-08

Use-after-free vulnerability in Apple Safari before 5.0 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper window management.

CVEs:CVE-2010-1750

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1770

macOSEPSS <= 49%HIGH2010-06-07

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, whic...

CVEs:CVE-2010-1770

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1421

macOSEPSS <= 49%MEDIUM2010-06-07

The execCommand JavaScript function in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict remote execution of clipboard commands, which allows remote attackers to mod...

CVEs:CVE-2010-1421

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-0542

OtherEPSS <= 49%CRITICAL2010-06-21

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap...

CVEs:CVE-2010-0542

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2010-1391

macOSEPSS <= 49%HIGH2010-06-08

Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database implementations in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allow remote attackers to cr...

CVEs:CVE-2010-1391

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1380

macOSEPSS <= 49%CRITICAL2010-06-16

Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page sizes.

CVEs:CVE-2010-1380

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1757

iOSEPSS <= 49%CRITICAL2010-06-22

WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user interface via a crafted HTML document.

CVEs:CVE-2010-1757

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1376

macOSEPSS <= 49%CRITICAL2010-06-16

Multiple format string vulnerabilities in Network Authorization in Apple Mac OS X 10.6 before 10.6.4 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) afp, (2) cifs, ...

CVEs:CVE-2010-1376

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1422

macOSEPSS <= 49%CRITICAL2010-06-07

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force ar...

CVEs:CVE-2010-1422

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1384

macOSEPSS <= 49%MEDIUM2010-06-08

Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to conduc...

CVEs:CVE-2010-1384

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1416

macOSEPSS <= 49%MEDIUM2010-06-07

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict the reading of a canvas that contains an SVG image pattern from a different web site, which allows remote attackers...

CVEs:CVE-2010-1416

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-0544

macOSEPSS <= 49%CRITICAL2010-06-08

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to a malformed ...

CVEs:CVE-2010-0544

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1389

macOSEPSS <= 49%CRITICAL2010-06-08

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving...

CVEs:CVE-2010-1389

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1390

macOSEPSS <= 49%CRITICAL2010-06-08

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF...

CVEs:CVE-2010-1390

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1394

macOSEPSS <= 49%CRITICAL2010-06-08

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML document...

CVEs:CVE-2010-1394

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1395

macOSEPSS <= 49%CRITICAL2010-06-08

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving DOM construct...

CVEs:CVE-2010-1395

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1418

macOSEPSS <= 49%CRITICAL2010-06-07

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via a FRAME element with a SRC attr...

CVEs:CVE-2010-1418

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-0541

macOSEPSS <= 49%CRITICAL2010-06-15

Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.

CVEs:CVE-2010-0541

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1388

macOSEPSS <= 49%HIGH2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a c...

CVEs:CVE-2010-1388

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1377

macOSEPSS <= 49%HIGH2010-06-16

Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified v...

CVEs:CVE-2010-1377

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1637

OtherEPSS <= 49%MEDIUM2010-06-22

The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.

CVEs:CVE-2010-1637

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1407

iOSEPSS <= 49%HIGH2010-06-22

WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML docu...

CVEs:CVE-2010-1407

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-2264

macOSEPSS <= 49%HIGH2010-06-11

The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle the :visited pseudo-class, which allows remote attackers to obtain...

CVEs:CVE-2010-2264

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-0543

macOSEPSS <= 49%CRITICAL2010-06-16

ImageIO in Apple Mac OS X 10.5.8, and 10.6 before 10.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with MPEG2 encoding.

CVEs:CVE-2010-0543

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1379

macOSEPSS <= 49%HIGH2010-06-16

Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of service (printing failure) by deploying a printing device that has a Unicode character in its printing...

CVEs:CVE-2010-1379

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1374

macOSEPSS <= 49%HIGH2010-06-16

Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AIM is used, allows remote attackers to create arbitrary files via directory traversal sequences in an inline image-transfer operation.

CVEs:CVE-2010-1374

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1406

macOSEPSS <= 49%HIGH2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote ...

CVEs:CVE-2010-1406

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1764

macOSEPSS <= 49%HIGH2010-06-08

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, follows multiple redirections during form submission, which allows remote web servers to obtain sensitive information by recording the form data.

CVEs:CVE-2010-1764

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-2432

OtherEPSS <= 49%HIGH2010-06-22

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNA...

CVEs:CVE-2010-2432

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2010-1393

macOSEPSS <= 49%MEDIUM2010-06-08

The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to discover sensitive URLs via an HREF attribute associated with a ...

CVEs:CVE-2010-1393

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-2441

SafariEPSS <= 49%HIGH2010-06-24

WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.

CVEs:CVE-2010-2441

Affected products

ProductStatusVendorPackageEcosystem
webkit affected apple
Upstream advisory

CVE-2010-2454

SafariEPSS <= 49%MEDIUM2010-06-25

Apple Safari does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-...

CVEs:CVE-2010-2454

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1381

macOSEPSS <= 49%LOW2010-06-16

The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enables support for wide links, which allows remote authenticated users to access arbitrary files via vectors involving symbolic links. NOTE: this might ove...

CVEs:CVE-2010-1381

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1382

macOSEPSS <= 49%HIGH2010-06-16

Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field.

CVEs:CVE-2010-1382

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0540

macOSEPSS <= 49%MEDIUM2010-06-15

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for re...

CVEs:CVE-2010-0540

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1373

macOSEPSS <= 49%CRITICAL2010-06-16

Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted help: URL, related to "URL parameters in HTML content."

CVEs:CVE-2010-1373

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-2431

OtherEPSS <= 49%MEDIUM2010-06-22

The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.

CVEs:CVE-2010-2431

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2010-1375

macOSEPSS <= 49%HIGH2010-06-16

NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to gain privileges via unspecified vectors.

CVEs:CVE-2010-1375

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0546

macOSEPSS <= 49%LOW2010-06-16

Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At Startup folder.

CVEs:CVE-2010-0546

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-0545

macOSEPSS <= 49%MEDIUM2010-06-16

The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an "Apply to enclosed items" action, which allows local users to bypass intended access restrictions via normal filesystem ...

CVEs:CVE-2010-0545

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.