Apple Security Advisories · February 2012 — Apple Security Advisories
23 advisories 23 CVEs

Apple-vendor CVEs for 2012-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-3966

OtherActive exploitation (sightings)CRITICAL2012-02-09

Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sheets (CSS) token-sequence data.

CVEs:CVE-2011-3966

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3026

OtherPoC exploitCRITICAL2012-02-15

Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.

CVEs:CVE-2011-3026

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2012-0841

OtherPoC exploitHIGH2012-02-23

libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.

CVEs:CVE-2012-0841

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2011-3460

macOSEPSS <= 49%CRITICAL2012-02-02

Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PNG file.

CVEs:CVE-2011-3460

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3453

macOSEPSS <= 49%CRITICAL2012-02-02

Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via crafted DNS data.

CVEs:CVE-2011-3453

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3457

macOSEPSS <= 49%CRITICAL2012-02-02

The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application ...

CVEs:CVE-2011-3457

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3459

macOSEPSS <= 49%CRITICAL2012-02-02

Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rdrf atom in a movie file that triggers a buffer overflow.

CVEs:CVE-2011-3459

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3458

macOSEPSS <= 49%CRITICAL2012-02-02

QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 file.

CVEs:CVE-2011-3458

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3448

macOSEPSS <= 49%CRITICAL2012-02-02

Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

CVEs:CVE-2011-3448

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3449

macOSEPSS <= 49%CRITICAL2012-02-02

Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.

CVEs:CVE-2011-3449

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3450

macOSEPSS <= 49%CRITICAL2012-02-02

CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via a long URL.

CVEs:CVE-2011-3450

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3021

OtherEPSS <= 49%CRITICAL2012-02-16

Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to subframe loading.

CVEs:CVE-2011-3021

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3462

macOSEPSS <= 49%HIGH2012-02-02

Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a diffe...

CVEs:CVE-2011-3462

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3016

OtherEPSS <= 49%CRITICAL2012-02-16

Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.

CVEs:CVE-2011-3016

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3027

OtherEPSS <= 49%HIGH2012-02-16

Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

CVEs:CVE-2011-3027

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3958

OtherEPSS <= 49%HIGH2012-02-09

Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

CVEs:CVE-2011-3958

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3969

OtherEPSS <= 49%CRITICAL2012-02-09

Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.

CVEs:CVE-2011-3969

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3971

OtherEPSS <= 49%CRITICAL2012-02-09

Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.

CVEs:CVE-2011-3971

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3968

OtherEPSS <= 49%CRITICAL2012-02-09

Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.

CVEs:CVE-2011-3968

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2011-3444

macOSEPSS <= 49%CRITICAL2012-02-02

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

CVEs:CVE-2011-3444

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3447

macOSEPSS <= 49%HIGH2012-02-02

CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.

CVEs:CVE-2011-3447

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3452

macOSEPSS <= 49%HIGH2012-02-02

Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.

CVEs:CVE-2011-3452

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2011-3463

macOSEPSS <= 49%HIGH2012-02-02

WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server or (2) a bound directory.

CVEs:CVE-2011-3463

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.