Apple Security Advisories · December 2010 — Apple Security Advisories
11 advisories 11 CVEs

Apple-vendor CVEs for 2010-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-4494

OtherPoC exploitCRITICAL2010-12-02

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath h...

CVEs:CVE-2010-4494

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
safari affected apple
Upstream advisory

CVE-2010-1804

OtherPoC exploitHIGH2010-12-16

Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) ...

CVEs:CVE-2010-1804

Affected products

ProductStatusVendorPackageEcosystem
airport_express affected apple
airport_express_base_station_firmware affected apple
airport_extreme affected apple
airport_extreme_base_station_firmware affected apple
time_capsule affected apple
Upstream advisory

CVE-2009-2189

OtherPoC exploitCRITICAL2010-12-16

The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote a...

CVEs:CVE-2009-2189

Affected products

ProductStatusVendorPackageEcosystem
airport_express affected apple
airport_express_base_station_firmware affected apple
airport_extreme affected apple
airport_extreme_base_station_firmware affected apple
time_capsule affected apple
Upstream advisory

CVE-2010-1508

OtherEPSS <= 49%HIGH2010-12-08

Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.

CVEs:CVE-2010-1508

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-3800

OtherEPSS <= 49%HIGH2010-12-08

Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.

CVEs:CVE-2010-3800

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-3801

OtherEPSS <= 49%HIGH2010-12-08

Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file.

CVEs:CVE-2010-3801

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-3802

OtherEPSS <= 49%HIGH2010-12-08

Integer signedness error in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted panorama atom in a QuickTime Virtual Reality (QTVR) movie file.

CVEs:CVE-2010-3802

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-4009

OtherEPSS <= 49%HIGH2010-12-08

Integer overflow in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

CVEs:CVE-2010-4009

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-0039

OtherEPSS <= 49%LOW2010-12-16

The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's I...

CVEs:CVE-2010-0039

Affected products

ProductStatusVendorPackageEcosystem
airport_express affected apple
airport_express_base_station_firmware affected apple
airport_extreme affected apple
airport_extreme_base_station_firmware affected apple
time_capsule affected apple
Upstream advisory

CVE-2010-0530

OtherEPSS <= 49%MEDIUM2010-12-08

Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory.

CVEs:CVE-2010-0530

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2010-4012

iOSEPSS <= 49%MEDIUM2010-12-08

Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.

CVEs:CVE-2010-4012

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.