Apple Security Advisories · November 2010 — Apple Security Advisories
64 advisories 64 CVEs

Apple-vendor CVEs for 2010-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-1840

macOSPoC exploitCRITICAL2010-11-12

Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecif...

CVEs:CVE-2010-1840

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1842

macOSPoC exploitHIGH2010-11-12

Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a bidirectional text string with ellipsis truncation.

CVEs:CVE-2010-1842

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1841

macOSPoC exploitHIGH2010-11-12

Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.

CVEs:CVE-2010-1841

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3798

macOSPoC exploitCRITICAL2010-11-12

Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive.

CVEs:CVE-2010-3798

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3785

macOSPoC exploitCRITICAL2010-11-12

Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document.

CVEs:CVE-2010-3785

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1831

macOSPoC exploitCRITICAL2010-11-12

Buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a long name of an embedded font in a document.

CVEs:CVE-2010-1831

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1832

macOSPoC exploitCRITICAL2010-11-12

Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a crafted embedded font in a document.

CVEs:CVE-2010-1832

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1836

macOSPoC exploitCRITICAL2010-11-12

Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

CVEs:CVE-2010-1836

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1846

macOSPoC exploitCRITICAL2010-11-12

Heap-based buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RAW image.

CVEs:CVE-2010-1846

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-4008

SafariPoC exploitHIGH2010-11-08

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to caus...

CVEs:CVE-2010-4008

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
safari affected apple
Upstream advisory

CVE-2010-4010

macOSPoC exploitCRITICAL2010-11-12

Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.

CVEs:CVE-2010-4010

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1837

macOSPoC exploitCRITICAL2010-11-12

CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a PDF document.

CVEs:CVE-2010-1837

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1845

macOSPoC exploitCRITICAL2010-11-12

ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image.

CVEs:CVE-2010-1845

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1833

macOSPoC exploitCRITICAL2010-11-12

Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.

CVEs:CVE-2010-1833

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3829

iOSPoC exploitMEDIUM2010-11-24

WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetching property, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading...

CVEs:CVE-2010-3829

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1828

macOSPoC exploitHIGH2010-11-12

AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets.

CVEs:CVE-2010-1828

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1829

macOSPoC exploitHIGH2010-11-12

Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to execute arbitrary code by creating files that are outside the bounds of a share.

CVEs:CVE-2010-1829

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1844

macOSPoC exploitHIGH2010-11-12

Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consumption and system crash) via a crafted image.

CVEs:CVE-2010-1844

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1803

macOSPoC exploitHIGH2010-11-12

Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.

CVEs:CVE-2010-1803

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3783

macOSPoC exploitMEDIUM2010-11-12

Password Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly perform replication, which allows remote authenticated users to bypass verification of the current password via unspecified vectors.

CVEs:CVE-2010-3783

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3784

macOSPoC exploitHIGH2010-11-12

The PMPageFormatCreateWithDataRepresentation API in Printing in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle XML data, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) via u...

CVEs:CVE-2010-3784

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3796

macOSPoC exploitHIGH2010-11-12

Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.

CVEs:CVE-2010-3796

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3797

macOSPoC exploitHIGH2010-11-12

Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVEs:CVE-2010-3797

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1378

macOSPoC exploitCRITICAL2010-11-12

OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.

CVEs:CVE-2010-1378

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1834

macOSPoC exploitMEDIUM2010-11-12

CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.

CVEs:CVE-2010-1834

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1830

macOSPoC exploitMEDIUM2010-11-12

AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depending on whether a share exists, which allows remote attackers to enumerate valid share names via unspecified vectors.

CVEs:CVE-2010-1830

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1838

macOSPoC exploitCRITICAL2010-11-12

Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.

CVEs:CVE-2010-1838

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1847

macOSPoC exploitMEDIUM2010-11-12

The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors.

CVEs:CVE-2010-1847

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3804

macOSEPSS <= 49%MEDIUM2010-11-19

The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers...

CVEs:CVE-2010-3804

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3812

macOSEPSS <= 49%HIGH2010-11-18

Integer overflow in the Text::wholeText method in dom/Text.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products allows remo...

CVEs:CVE-2010-3812

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3805

macOSEPSS <= 49%HIGH2010-11-19

Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involv...

CVEs:CVE-2010-3805

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3824

macOSEPSS <= 49%HIGH2010-11-19

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vec...

CVEs:CVE-2010-3824

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3803

macOSEPSS <= 49%HIGH2010-11-19

Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string.

CVEs:CVE-2010-3803

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3811

macOSEPSS <= 49%HIGH2010-11-19

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vec...

CVEs:CVE-2010-3811

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3816

macOSEPSS <= 49%HIGH2010-11-19

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vec...

CVEs:CVE-2010-3816

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3818

macOSEPSS <= 49%HIGH2010-11-19

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vec...

CVEs:CVE-2010-3818

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3823

macOSEPSS <= 49%HIGH2010-11-19

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vec...

CVEs:CVE-2010-3823

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3787

macOSEPSS <= 49%CRITICAL2010-11-12

Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.

CVEs:CVE-2010-3787

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3790

macOSEPSS <= 49%CRITICAL2010-11-12

QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file that causes an image sample transformation to scale a spr...

CVEs:CVE-2010-3790

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
quicktime affected apple
Upstream advisory

CVE-2010-3808

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of editing commands, which allows remote attackers to execut...

CVEs:CVE-2010-3808

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3809

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of inline styling, which allows remote attackers to execute ...

CVEs:CVE-2010-3809

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3817

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of Cascading Style Sheets (CSS) 3D transforms, which allows ...

CVEs:CVE-2010-3817

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3819

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of Cascading Style Sheets (CSS) boxes, which allows remote a...

CVEs:CVE-2010-3819

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3820

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses uninitialized memory during processing of editable elements, which allows remote attackers to execute arbitrary code or cause a d...

CVEs:CVE-2010-3820

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3822

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses an uninitialized pointer during processing of Cascading Style Sheets (CSS) counter styles, which allows remote attackers to execu...

CVEs:CVE-2010-3822

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3826

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of colors in an SVG document, which allows remote attackers ...

CVEs:CVE-2010-3826

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3821

macOSEPSS <= 49%HIGH2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the :first-letter pseudo-element in a Cascading Style Sheets (CSS) token sequence, which allows remote attackers ...

CVEs:CVE-2010-3821

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3786

macOSEPSS <= 49%CRITICAL2010-11-12

QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Excel file.

CVEs:CVE-2010-3786

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3832

iOSEPSS <= 49%CRITICAL2010-11-24

Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband processor via a crafted Temporary Mobile Subscriber I...

CVEs:CVE-2010-3832

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-3791

macOSEPSS <= 49%CRITICAL2010-11-12

Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

CVEs:CVE-2010-3791

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
quicktime affected apple
Upstream advisory

CVE-2010-3788

macOSEPSS <= 49%CRITICAL2010-11-12

QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 file.

CVEs:CVE-2010-3788

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
quicktime affected apple
Upstream advisory

CVE-2010-3792

macOSEPSS <= 49%CRITICAL2010-11-12

Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

CVEs:CVE-2010-3792

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
quicktime affected apple
Upstream advisory

CVE-2010-3794

macOSEPSS <= 49%CRITICAL2010-11-12

QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Fl...

CVEs:CVE-2010-3794

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3795

macOSEPSS <= 49%CRITICAL2010-11-12

QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.

CVEs:CVE-2010-3795

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-1843

macOSEPSS <= 49%HIGH2010-11-12

Networking in Apple Mac OS X 10.6.2 through 10.6.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted PIM packet.

CVEs:CVE-2010-1843

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3789

macOSEPSS <= 49%CRITICAL2010-11-12

QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted AVI file.

CVEs:CVE-2010-3789

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
quicktime affected apple
Upstream advisory

CVE-2010-3793

macOSEPSS <= 49%CRITICAL2010-11-12

QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie file.

CVEs:CVE-2010-3793

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
quicktime affected apple
Upstream advisory

CVE-2010-3810

macOSEPSS <= 49%MEDIUM2010-11-19

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the History object, which allows remote attackers to spoof the location bar's URL or add URLs to the history via ...

CVEs:CVE-2010-3810

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3813

macOSEPSS <= 49%MEDIUM2010-11-18

The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other ...

CVEs:CVE-2010-3813

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-3827

iOSEPSS <= 49%MEDIUM2010-11-24

Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via unspecified vectors.

CVEs:CVE-2010-3827

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-3831

iOSEPSS <= 49%MEDIUM2010-11-24

Photos in Apple iOS before 4.2 enables support for HTTP Basic Authentication over an unencrypted connection, which allows man-in-the-middle attackers to read MobileMe account passwords by spoofing a MobileMe Gallery server during a "Send to MobileMe" a...

CVEs:CVE-2010-3831

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-3828

iOSEPSS <= 49%MEDIUM2010-11-24

iAd Content Display in Apple iOS before 4.2 allows man-in-the-middle attackers to make calls via a crafted URL in an ad.

CVEs:CVE-2010-3828

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-4011

macOSEPSS <= 49%MEDIUM2010-11-16

Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's ow...

CVEs:CVE-2010-4011

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

CVE-2010-3830

iOSEPSS <= 49%HIGH2010-11-24

Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privileges via unspecified vectors.

CVEs:CVE-2010-3830

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.