Advisories
macOSWeaponized exploitHIGH2011-03-22
The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.
CVEs:CVE-2011-0182
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
SafariActive exploitation (sightings)CRITICAL2011-03-11
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.
CVEs:CVE-2011-0167
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariPoC exploitHIGH2011-03-10
Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vec...
CVEs:CVE-2011-1290
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| webkit |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2011-03-02
Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash)...
CVEs:CVE-2011-0192
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2011-03-03
Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile i...
CVEs:CVE-2011-0170
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
SafariPoC exploitCRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0164
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2011-03-22
The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via vectors involving a cross-site redirect.
CVEs:CVE-2011-0187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| quicktime |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2011-03-01
Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."
CVEs:CVE-2011-1117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2011-03-11
Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.
CVEs:CVE-2011-1204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2011-03-02
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressio...
CVEs:CVE-2010-4754
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-03-03
Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted...
CVEs:CVE-2011-0191
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
iOSEPSS <= 49%CRITICAL2011-03-10
Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding chi...
CVEs:CVE-2011-1344
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-11
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application ...
CVEs:CVE-2011-1417
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle att...
CVEs:CVE-2011-0115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption a...
CVEs:CVE-2011-0116
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, allows man-in-the-middle attackers to...
CVEs:CVE-2011-0132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with pseudo-elements, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial ...
CVEs:CVE-2011-0133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly parse HTML elements associated with document namespaces, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and ap...
CVEs:CVE-2011-0149
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an Excel spreadsheet with a crafted formula that uses unspecified opcodes.
CVEs:CVE-2011-0184
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
tvOSEPSS <= 49%HIGH2011-03-11
Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.
CVEs:CVE-2011-0162
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apple_tv |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image.
CVEs:CVE-2011-0181
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| imageio |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.
CVEs:CVE-2011-0175
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.
CVEs:CVE-2011-0176
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.
CVEs:CVE-2011-0177
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.
CVEs:CVE-2011-0193
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0152
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corrupti...
CVEs:CVE-2011-0154
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0112
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0113
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0114
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0119
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0124
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0126
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0130
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0141
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0142
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0143
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0144
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0145
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0147
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0148
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0150
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0151
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0153
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0156
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0168
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.
CVEs:CVE-2011-0186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| quicktime |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.
CVEs:CVE-2011-0194
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| imageio |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.
CVEs:CVE-2011-0179
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0139
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-03
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulner...
CVEs:CVE-2011-0165
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
CVEs:CVE-2011-0174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
SafariEPSS <= 49%HIGH2011-03-11
The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overl...
CVEs:CVE-2011-0166
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-03-25
Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
CVEs:CVE-2011-1296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-03-01
Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
CVEs:CVE-2011-1114
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-03-01
Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
CVEs:CVE-2011-1115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-03-01
Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.
CVEs:CVE-2011-1121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-03-25
Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2011-1293
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2011-03-22
Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an...
CVEs:CVE-2011-0183
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%MEDIUM2011-03-11
The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
CVEs:CVE-2011-1190
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-03-11
Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
CVEs:CVE-2011-1203
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
iOSEPSS <= 49%CRITICAL2011-03-11
WebKit, as used in Apple iOS before 4.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2011-...
CVEs:CVE-2011-0157
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-03-11
Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2011-1188
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-25
WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, o...
CVEs:CVE-2011-1295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-03-01
Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale...
CVEs:CVE-2011-1109
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2011-03-22
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (...
CVEs:CVE-2011-0173
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| applescript |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
iOSEPSS <= 49%MEDIUM2011-03-11
The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari application, which might make it easier for remote web servers to track users by setting a cookie.
CVEs:CVE-2011-0159
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
iOSEPSS <= 49%MEDIUM2011-03-11
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web ...
CVEs:CVE-2011-0161
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
iOSEPSS <= 49%CRITICAL2011-03-11
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-...
CVEs:CVE-2011-0163
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
iOSEPSS <= 49%MEDIUM2011-03-11
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
CVEs:CVE-2011-0160
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2011-03-11
WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scri...
CVEs:CVE-2011-0169
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2011-03-11
The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier for remote IPv6 servers to track...
CVEs:CVE-2011-1418
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apple_tv |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
OtherEPSS <= 49%MEDIUM2011-03-01
Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.
CVEs:CVE-2011-1107
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2011-03-22
Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an A...
CVEs:CVE-2011-0190
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| installer |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
iOSEPSS <= 49%HIGH2011-03-11
MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL handlers, which allows remote attackers to cause a denial of service (persistent application crash) via crafted JavaScript code.
CVEs:CVE-2011-0158
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2011-03-22
The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulne...
CVEs:CVE-2011-0189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
| terminal |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2011-03-22
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.
CVEs:CVE-2011-0180
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2011-03-22
AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.
CVEs:CVE-2011-0172
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2011-03-04
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of file...
CVEs:CVE-2011-1073
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2011-03-22
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this dire...
CVEs:CVE-2011-0178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| carboncore |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |