Apple Security Advisories · October 2011 — Apple Security Advisories
85 advisories 85 CVEs

Apple-vendor CVEs for 2011-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-3230

macOSWeaponized exploitCRITICAL2011-10-13

Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.

CVEs:CVE-2011-3230

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-3216

macOSWeaponized exploitLOW2011-10-13

The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.

CVEs:CVE-2011-3216

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3251

OtherActive exploitation (sightings)HIGH2011-10-28

Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file.

CVEs:CVE-2011-3251

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2011-3252

OtherPoC exploitHIGH2011-10-12

Buffer overflow in CoreAudio, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Advanced Audio Coding (AAC) stream.

CVEs:CVE-2011-3252

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2011-3250

OtherPoC exploitHIGH2011-10-28

Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.

CVEs:CVE-2011-3250

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2011-3219

OtherPoC exploitHIGH2011-10-12

Buffer overflow in CoreMedia, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

CVEs:CVE-2011-3219

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2011-3238

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3238

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-0259

OtherPoC exploitCRITICAL2011-10-12

CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecifie...

CVEs:CVE-2011-0259

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2011-3233

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3233

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3239

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3239

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3241

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3241

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2813

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2813

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2814

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2814

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2815

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2815

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2811

SafariPoC exploitCRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2811

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3249

OtherEPSS <= 49%HIGH2011-10-28

Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with FLC encoding.

CVEs:CVE-2011-3249

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2011-3248

OtherEPSS <= 49%HIGH2011-10-26

Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file.

CVEs:CVE-2011-3248

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2011-3256

iOSEPSS <= 49%CRITICAL2011-10-13

FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a ...

CVEs:CVE-2011-3256

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-2873

iOSEPSS <= 49%HIGH2011-10-06

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2873

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-0230

macOSEPSS <= 49%CRITICAL2011-10-13

Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2011-0230

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3247

OtherEPSS <= 49%HIGH2011-10-28

Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT file.

CVEs:CVE-2011-3247

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2011-3222

macOSEPSS <= 49%CRITICAL2011-10-13

Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.

CVEs:CVE-2011-3222

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3223

macOSEPSS <= 49%CRITICAL2011-10-13

Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.

CVEs:CVE-2011-3223

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3260

iOSEPSS <= 49%CRITICAL2011-10-13

Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word document.

CVEs:CVE-2011-3260

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3228

macOSEPSS <= 49%CRITICAL2011-10-13

QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

CVEs:CVE-2011-3228

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3246

macOSEPSS <= 49%MEDIUM2011-10-13

CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2...

CVEs:CVE-2011-3246

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3437

macOSEPSS <= 49%CRITICAL2011-10-13

Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.

CVEs:CVE-2011-3437

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3221

macOSEPSS <= 49%CRITICAL2011-10-13

QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.

CVEs:CVE-2011-3221

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3261

iOSEPSS <= 49%CRITICAL2011-10-13

Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Excel spreadsheet.

CVEs:CVE-2011-3261

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-0224

macOSEPSS <= 49%CRITICAL2011-10-13

CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.

CVEs:CVE-2011-0224

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3217

macOSEPSS <= 49%CRITICAL2011-10-13

MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.

CVEs:CVE-2011-3217

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3235

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3235

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3236

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3236

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3237

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3237

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2356

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2356

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2352

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2352

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2354

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2354

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3244

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-3244

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2338

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2338

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2341

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2341

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2809

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2809

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3259

tvOSEPSS <= 49%CRITICAL2011-10-13

The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remote attackers to cause a denial of service (resource consumption) by making many connection attempts.

CVEs:CVE-2011-3259

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
Upstream advisory

CVE-2011-2339

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2339

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2816

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2816

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2817

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2817

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2820

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2820

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-2831

SafariEPSS <= 49%CRITICAL2011-10-12

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2831

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3432

iOSEPSS <= 49%HIGH2011-10-13

The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.

CVEs:CVE-2011-3432

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-0229

macOSEPSS <= 49%CRITICAL2011-10-13

Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access.

CVEs:CVE-2011-0229

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3885

OtherEPSS <= 49%CRITICAL2011-10-25

Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.

CVEs:CVE-2011-3885

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3229

SafariEPSS <= 49%CRITICAL2011-10-13

Directory traversal vulnerability in Apple Safari before 5.1.1 allows remote attackers to execute arbitrary JavaScript code, in a Safari Extensions context, via a crafted safari-extension: URL.

CVEs:CVE-2011-3229

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-3226

macOSEPSS <= 49%MEDIUM2011-10-13

Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account.

CVEs:CVE-2011-3226

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3243

iOSEPSS <= 49%CRITICAL2011-10-13

Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.

CVEs:CVE-2011-3243

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-3225

macOSEPSS <= 49%MEDIUM2011-10-13

The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging...

CVEs:CVE-2011-3225

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3220

macOSEPSS <= 49%HIGH2011-10-13

QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.

CVEs:CVE-2011-3220

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3227

macOSEPSS <= 49%CRITICAL2011-10-13

libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (appli...

CVEs:CVE-2011-3227

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3426

iOSEPSS <= 49%CRITICAL2011-10-13

Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.

CVEs:CVE-2011-3426

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3224

macOSEPSS <= 49%CRITICAL2011-10-13

The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.

CVEs:CVE-2011-3224

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3881

SafariEPSS <= 49%CRITICAL2011-10-25

WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selecti...

CVEs:CVE-2011-3881

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-3430

iOSEPSS <= 49%HIGH2011-10-13

The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect conf...

CVEs:CVE-2011-3430

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3436

macOSEPSS <= 49%HIGH2011-10-13

Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended worksta...

CVEs:CVE-2011-3436

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3434

iOSEPSS <= 49%HIGH2011-10-13

The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.

CVEs:CVE-2011-3434

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3255

iOSEPSS <= 49%HIGH2011-10-13

CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.

CVEs:CVE-2011-3255

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3888

OtherEPSS <= 49%CRITICAL2011-10-25

Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug...

CVEs:CVE-2011-3888

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3242

macOSEPSS <= 49%MEDIUM2011-10-13

The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of the Block Cookies setting, which makes it easier for remote web servers to track users via a cookie.

CVEs:CVE-2011-3242

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-0231

macOSEPSS <= 49%MEDIUM2011-10-13

CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."

CVEs:CVE-2011-0231

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3887

OtherEPSS <= 49%MEDIUM2011-10-25

Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.

CVEs:CVE-2011-3887

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-2877

OtherEPSS <= 49%HIGH2011-10-04

Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale font."

CVEs:CVE-2011-2877

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3231

macOSEPSS <= 49%CRITICAL2011-10-13

The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates, which allows remote web servers to execute arbitrary code via a crafted certificate.

CVEs:CVE-2011-3231

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-3218

macOSEPSS <= 49%CRITICAL2011-10-13

The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the ...

CVEs:CVE-2011-3218

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3254

iOSEPSS <= 49%CRITICAL2011-10-13

Cross-site scripting (XSS) vulnerability in Calendar in Apple iOS before 5 allows remote attackers to inject arbitrary web script or HTML via an invitation note.

CVEs:CVE-2011-3254

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-2845

OtherEPSS <= 49%MEDIUM2011-10-25

Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.

CVEs:CVE-2011-2845

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-3213

macOSEPSS <= 49%HIGH2011-10-13

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communicat...

CVEs:CVE-2011-3213

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3427

tvOSEPSS <= 49%HIGH2011-10-13

The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive inf...

CVEs:CVE-2011-3427

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
Upstream advisory

CVE-2011-3435

macOSEPSS <= 49%LOW2011-10-13

Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.

CVEs:CVE-2011-3435

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3253

iOSEPSS <= 49%HIGH2011-10-13

CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive information via an arbitrary certificate.

CVEs:CVE-2011-3253

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3212

macOSEPSS <= 49%HIGH2011-10-13

CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the dis...

CVEs:CVE-2011-3212

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3245

iOSEPSS <= 49%HIGH2011-10-13

The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.

CVEs:CVE-2011-3245

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3429

iOSEPSS <= 49%HIGH2011-10-13

The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, which might allow physically proximate attackers to obtain sensitive information by reading this file.

CVEs:CVE-2011-3429

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3431

iOSEPSS <= 49%LOW2011-10-13

The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen.

CVEs:CVE-2011-3431

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3215

macOSEPSS <= 49%LOW2011-10-13

The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allows physically proximate attackers to bypass intended access restrictions and discover a password by making a DMA request in the (1) l...

CVEs:CVE-2011-3215

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-0260

macOSEPSS <= 49%MEDIUM2011-10-13

The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing in...

CVEs:CVE-2011-0260

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3214

macOSEPSS <= 49%MEDIUM2011-10-13

IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.

CVEs:CVE-2011-3214

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3257

iOSEPSS <= 49%LOW2011-10-13

The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a dif...

CVEs:CVE-2011-3257

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-0185

macOSEPSS <= 49%MEDIUM2011-10-13

Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.

CVEs:CVE-2011-0185

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.