Advisories
OtherPoC exploitCRITICAL2010-12-02
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath h...
CVEs:CVE-2010-4494
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2010-12-16
Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) ...
CVEs:CVE-2010-1804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| airport_express |
affected |
apple |
— |
— |
| airport_express_base_station_firmware |
affected |
apple |
— |
— |
| airport_extreme |
affected |
apple |
— |
— |
| airport_extreme_base_station_firmware |
affected |
apple |
— |
— |
| time_capsule |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2010-12-16
The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote a...
CVEs:CVE-2009-2189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| airport_express |
affected |
apple |
— |
— |
| airport_express_base_station_firmware |
affected |
apple |
— |
— |
| airport_extreme |
affected |
apple |
— |
— |
| airport_extreme_base_station_firmware |
affected |
apple |
— |
— |
| time_capsule |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2010-12-08
Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.
CVEs:CVE-2010-1508
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2010-12-08
Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.
CVEs:CVE-2010-3800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2010-12-08
Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file.
CVEs:CVE-2010-3801
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2010-12-08
Integer signedness error in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted panorama atom in a QuickTime Virtual Reality (QTVR) movie file.
CVEs:CVE-2010-3802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2010-12-08
Integer overflow in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
CVEs:CVE-2010-4009
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%LOW2010-12-16
The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's I...
CVEs:CVE-2010-0039
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| airport_express |
affected |
apple |
— |
— |
| airport_express_base_station_firmware |
affected |
apple |
— |
— |
| airport_extreme |
affected |
apple |
— |
— |
| airport_extreme_base_station_firmware |
affected |
apple |
— |
— |
| time_capsule |
affected |
apple |
— |
— |
OtherEPSS <= 49%MEDIUM2010-12-08
Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory.
CVEs:CVE-2010-0530
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
iOSEPSS <= 49%MEDIUM2010-12-08
Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.
CVEs:CVE-2010-4012
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |