Apple Security Advisories · March 2011 — Apple Security Advisories
99 advisories 99 CVEs

Apple-vendor CVEs for 2011-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-0182

macOSWeaponized exploitHIGH2011-03-22

The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.

CVEs:CVE-2011-0182

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0167

SafariActive exploitation (sightings)CRITICAL2011-03-11

The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.

CVEs:CVE-2011-0167

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-1290

SafariPoC exploitHIGH2011-03-10

Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vec...

CVEs:CVE-2011-1290

Affected products

ProductStatusVendorPackageEcosystem
webkit affected apple
Upstream advisory

CVE-2011-0192

OtherPoC exploitHIGH2011-03-02

Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash)...

CVEs:CVE-2011-0192

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2011-0170

OtherPoC exploitHIGH2011-03-03

Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile i...

CVEs:CVE-2011-0170

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2011-0164

SafariPoC exploitCRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0164

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0187

macOSPoC exploitMEDIUM2011-03-22

The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via vectors involving a cross-site redirect.

CVEs:CVE-2011-0187

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
quicktime affected apple
Upstream advisory

CVE-2011-1117

OtherPoC exploitHIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."

CVEs:CVE-2011-1117

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1204

OtherPoC exploitHIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.

CVEs:CVE-2011-1204

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2010-4754

macOSPoC exploitMEDIUM2011-03-02

The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressio...

CVEs:CVE-2010-4754

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2011-0191

OtherEPSS <= 49%HIGH2011-03-03

Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted...

CVEs:CVE-2011-0191

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2011-1344

iOSEPSS <= 49%CRITICAL2011-03-10

Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding chi...

CVEs:CVE-2011-1344

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-1417

macOSEPSS <= 49%CRITICAL2011-03-11

Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application ...

CVEs:CVE-2011-1417

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0115

SafariEPSS <= 49%CRITICAL2011-03-03

The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle att...

CVEs:CVE-2011-0115

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-0116

SafariEPSS <= 49%CRITICAL2011-03-03

Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption a...

CVEs:CVE-2011-0116

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0132

SafariEPSS <= 49%CRITICAL2011-03-03

Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, allows man-in-the-middle attackers to...

CVEs:CVE-2011-0132

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-0133

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with pseudo-elements, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial ...

CVEs:CVE-2011-0133

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0149

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly parse HTML elements associated with document namespaces, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and ap...

CVEs:CVE-2011-0149

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0184

macOSEPSS <= 49%CRITICAL2011-03-22

QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an Excel spreadsheet with a crafted formula that uses unspecified opcodes.

CVEs:CVE-2011-0184

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0162

tvOSEPSS <= 49%HIGH2011-03-11

Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.

CVEs:CVE-2011-0162

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2011-0181

macOSEPSS <= 49%CRITICAL2011-03-22

Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image.

CVEs:CVE-2011-0181

Affected products

ProductStatusVendorPackageEcosystem
imageio affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0175

macOSEPSS <= 49%CRITICAL2011-03-22

Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.

CVEs:CVE-2011-0175

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0176

macOSEPSS <= 49%CRITICAL2011-03-22

Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.

CVEs:CVE-2011-0176

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0177

macOSEPSS <= 49%CRITICAL2011-03-22

Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.

CVEs:CVE-2011-0177

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0193

macOSEPSS <= 49%CRITICAL2011-03-22

Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.

CVEs:CVE-2011-0193

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0152

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0152

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0155

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0155

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0154

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corrupti...

CVEs:CVE-2011-0154

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2011-0112

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0112

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0113

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0113

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0114

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0114

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0117

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0117

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0118

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0118

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0119

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0119

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0120

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0120

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0121

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0121

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0122

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0122

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0123

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0123

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0124

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0124

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0125

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0125

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0126

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0126

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0127

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0127

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0128

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0128

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0129

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0129

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0130

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0130

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0131

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0131

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0134

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0134

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0135

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0135

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0136

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0136

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0137

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0137

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0138

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0138

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0140

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0140

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0141

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0141

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0142

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0142

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0143

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0143

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0144

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0144

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0145

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0145

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0146

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0146

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0147

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0147

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0148

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0148

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0150

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0150

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0151

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0151

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0153

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0153

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0156

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0156

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0168

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0168

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0186

macOSEPSS <= 49%CRITICAL2011-03-22

QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.

CVEs:CVE-2011-0186

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
quicktime affected apple
Upstream advisory

CVE-2011-0194

macOSEPSS <= 49%CRITICAL2011-03-22

Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.

CVEs:CVE-2011-0194

Affected products

ProductStatusVendorPackageEcosystem
imageio affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0179

macOSEPSS <= 49%CRITICAL2011-03-22

CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.

CVEs:CVE-2011-0179

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0139

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0139

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0165

SafariEPSS <= 49%CRITICAL2011-03-03

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...

CVEs:CVE-2011-0165

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0174

macOSEPSS <= 49%CRITICAL2011-03-22

Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.

CVEs:CVE-2011-0174

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0166

SafariEPSS <= 49%HIGH2011-03-11

The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overl...

CVEs:CVE-2011-0166

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-1296

OtherEPSS <= 49%HIGH2011-03-25

Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1296

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1114

OtherEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

CVEs:CVE-2011-1114

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1115

OtherEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1115

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1121

OtherEPSS <= 49%CRITICAL2011-03-01

Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.

CVEs:CVE-2011-1121

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1293

OtherEPSS <= 49%CRITICAL2011-03-25

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1293

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-0183

macOSEPSS <= 49%HIGH2011-03-22

Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an...

CVEs:CVE-2011-0183

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-1190

OtherEPSS <= 49%MEDIUM2011-03-11

The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."

CVEs:CVE-2011-1190

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-1203

OtherEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1203

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-0157

iOSEPSS <= 49%CRITICAL2011-03-11

WebKit, as used in Apple iOS before 4.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2011-...

CVEs:CVE-2011-0157

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
webkit affected apple
Upstream advisory

CVE-2011-1188

OtherEPSS <= 49%CRITICAL2011-03-11

Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1188

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1295

SafariEPSS <= 49%CRITICAL2011-03-25

WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, o...

CVEs:CVE-2011-1295

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-1109

OtherEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale...

CVEs:CVE-2011-1109

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-0173

macOSEPSS <= 49%CRITICAL2011-03-22

Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (...

CVEs:CVE-2011-0173

Affected products

ProductStatusVendorPackageEcosystem
applescript affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0159

iOSEPSS <= 49%MEDIUM2011-03-11

The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari application, which might make it easier for remote web servers to track users by setting a cookie.

CVEs:CVE-2011-0159

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-0161

iOSEPSS <= 49%MEDIUM2011-03-11

WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web ...

CVEs:CVE-2011-0161

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-0163

iOSEPSS <= 49%CRITICAL2011-03-11

WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-...

CVEs:CVE-2011-0163

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-0160

iOSEPSS <= 49%MEDIUM2011-03-11

WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.

CVEs:CVE-2011-0160

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-0169

SafariEPSS <= 49%CRITICAL2011-03-11

WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scri...

CVEs:CVE-2011-0169

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-1418

tvOSEPSS <= 49%CRITICAL2011-03-11

The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier for remote IPv6 servers to track...

CVEs:CVE-2011-1418

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2011-1107

OtherEPSS <= 49%MEDIUM2011-03-01

Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.

CVEs:CVE-2011-1107

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-0190

macOSEPSS <= 49%MEDIUM2011-03-22

Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an A...

CVEs:CVE-2011-0190

Affected products

ProductStatusVendorPackageEcosystem
installer affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0158

iOSEPSS <= 49%HIGH2011-03-11

MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL handlers, which allows remote attackers to cause a denial of service (persistent application crash) via crafted JavaScript code.

CVEs:CVE-2011-0158

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-0189

macOSEPSS <= 49%MEDIUM2011-03-22

The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulne...

CVEs:CVE-2011-0189

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
terminal affected apple
Upstream advisory

CVE-2011-0180

macOSEPSS <= 49%HIGH2011-03-22

Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.

CVEs:CVE-2011-0180

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0172

macOSEPSS <= 49%HIGH2011-03-22

AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.

CVEs:CVE-2011-0172

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-1073

macOSEPSS <= 49%MEDIUM2011-03-04

crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of file...

CVEs:CVE-2011-1073

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2011-0178

macOSEPSS <= 49%MEDIUM2011-03-22

The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this dire...

CVEs:CVE-2011-0178

Affected products

ProductStatusVendorPackageEcosystem
carboncore affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.