Advisories
OtherWeaponized exploitHIGH2011-08-04
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.
CVEs:CVE-2011-0257
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2011-08-22
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
CVEs:CVE-2011-2821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2011-08-23
Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a line box.
CVEs:CVE-2011-2823
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2011-08-03
Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
CVEs:CVE-2011-2359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2011-08-03
Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.
CVEs:CVE-2011-2788
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherPoC exploitMEDIUM2011-08-03
Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.
CVEs:CVE-2011-2819
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-15
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in G...
CVEs:CVE-2011-2896
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cups |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSC atoms in a QuickTime movie file.
CVEs:CVE-2011-0249
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSS atoms in a QuickTime movie file.
CVEs:CVE-2011-0250
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSZ atoms in a QuickTime movie file.
CVEs:CVE-2011-0251
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STTS atoms in a QuickTime movie file.
CVEs:CVE-2011-0252
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Multiple stack-based buffer overflows in Apple QuickTime before 7.7 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie.
CVEs:CVE-2011-0247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pict file.
CVEs:CVE-2011-0245
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Heap-based buffer overflow in Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.
CVEs:CVE-2011-0246
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-19
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a c...
CVEs:CVE-2011-3170
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cups |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Integer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted track run atoms in a QuickTime movie file.
CVEs:CVE-2011-0256
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-04
Stack-based buffer overflow in the QuickTime ActiveX control in Apple QuickTime before 7.7 on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTL ...
CVEs:CVE-2011-0248
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-23
Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving custom fonts.
CVEs:CVE-2011-2825
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-23
Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text searching.
CVEs:CVE-2011-2827
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-03
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.
CVEs:CVE-2011-2790
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-03
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.
CVEs:CVE-2011-2797
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-03
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.
CVEs:CVE-2011-2799
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-03
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.
CVEs:CVE-2011-2792
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2011-08-03
Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.
CVEs:CVE-2011-2800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-03
Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.
CVEs:CVE-2011-2805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2011-08-03
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.
CVEs:CVE-2011-2818
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
SafariEPSS <= 49%MEDIUM2011-08-09
Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Str...
CVEs:CVE-2008-7296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |