Apple Security Advisories · March 2012 — Apple Security Advisories
97 advisories 97 CVEs

Apple-vendor CVEs for 2012-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2012-0607

iOSPoC exploitHIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0607

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0634

SafariPoC exploitCRITICAL2012-03-08

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2012-0634

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2011-3038

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.

CVEs:CVE-2011-3038

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3032

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG values.

CVEs:CVE-2011-3032

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3037

OtherPoC exploitHIGH2012-03-04

Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

CVEs:CVE-2011-3037

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3042

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of table sections.

CVEs:CVE-2011-3042

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3034

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.

CVEs:CVE-2011-3034

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3035

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.

CVEs:CVE-2011-3035

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3036

OtherPoC exploitHIGH2012-03-04

Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

CVEs:CVE-2011-3036

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3039

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to quote handling.

CVEs:CVE-2011-3039

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3040

OtherPoC exploitHIGH2012-03-04

Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

CVEs:CVE-2011-3040

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3041

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of class attributes.

CVEs:CVE-2011-3041

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3043

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of eleme...

CVEs:CVE-2011-3043

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3044

OtherPoC exploitCRITICAL2012-03-04

Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animation elements.

CVEs:CVE-2011-3044

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2012-0592

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0592

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0643

iOSEPSS <= 49%HIGH2012-03-08

The kernel in Apple iOS before 5.1 does not properly handle debug system calls, which allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a crafted program.

CVEs:CVE-2012-0643

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2012-0646

iOSEPSS <= 49%HIGH2012-03-08

Format string vulnerability in VPN in Apple iOS before 5.1 allows remote attackers to execute arbitrary code via a crafted racoon configuration file.

CVEs:CVE-2012-0646

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3046

OtherEPSS <= 49%HIGH2012-03-08

The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.

CVEs:CVE-2011-3046

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2012-0642

iOSEPSS <= 49%HIGH2012-03-08

Integer underflow in Apple iOS before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (device crash) via a crafted catalog file in an HFS disk image.

CVEs:CVE-2012-0642

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-2833

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2833

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-2867

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2867

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-2868

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2868

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-2869

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2869

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-2870

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2870

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-2871

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2871

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-2872

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2011-2872

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0591

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0591

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0593

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0593

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0594

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0594

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0595

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0595

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0596

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0596

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0597

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0597

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0598

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0598

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0599

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0599

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0600

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0600

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0601

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0601

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0602

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0602

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0603

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0603

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0604

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0604

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0605

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0605

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0606

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0606

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0609

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0609

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0610

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0610

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0611

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0611

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0612

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0612

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0613

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0613

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0614

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0614

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0615

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0615

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0616

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0616

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0617

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0617

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0618

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0618

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0619

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0619

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0620

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0620

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0621

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0621

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0622

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0622

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0623

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0623

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0624

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0624

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0625

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0625

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0626

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0626

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0627

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0627

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0628

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0628

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0629

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0629

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0630

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0630

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0631

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0631

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0632

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0632

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0633

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0633

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-0635

iOSEPSS <= 49%HIGH2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0635

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2012-1148

OtherEPSS <= 49%HIGH2012-03-09

Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation f...

CVEs:CVE-2012-1148

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2011-3845

SafariEPSS <= 49%HIGH2012-03-08

Use-after-free vulnerability in Apple Safari 5.1.2, when a plug-in with a blocking function is installed, allows user-assisted remote attackers to execute arbitrary code via a crafted web page that is accessed during user interaction with the plug-in, ...

CVEs:CVE-2011-3845

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-0608

iOSEPSS <= 49%CRITICAL2012-03-08

WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit...

CVEs:CVE-2012-0608

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2011-2866

SafariEPSS <= 49%CRITICAL2012-03-08

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2011-2866

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2012-0585

iOSEPSS <= 49%MEDIUM2012-03-08

The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method.

CVEs:CVE-2012-0585

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2012-0636

SafariEPSS <= 49%CRITICAL2012-03-08

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2012-0636

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2012-0637

SafariEPSS <= 49%CRITICAL2012-03-08

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2012-0637

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2012-0638

SafariEPSS <= 49%CRITICAL2012-03-08

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2012-0638

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2012-0639

SafariEPSS <= 49%CRITICAL2012-03-08

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2012-0639

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2012-0648

SafariEPSS <= 49%CRITICAL2012-03-08

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability tha...

CVEs:CVE-2012-0648

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
webkit affected apple
Upstream advisory

CVE-2012-0641

iOSEPSS <= 49%HIGH2012-03-08

CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447.

CVEs:CVE-2012-0641

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3060

OtherEPSS <= 49%HIGH2012-03-28

Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3060

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3050

OtherEPSS <= 49%CRITICAL2012-03-21

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter ...

CVEs:CVE-2011-3050

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3064

OtherEPSS <= 49%CRITICAL2012-03-28

Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.

CVEs:CVE-2011-3064

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2012-0590

iOSEPSS <= 49%CRITICAL2012-03-08

Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a drag-and-drop operation.

CVEs:CVE-2012-0590

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2012-0586

iOSEPSS <= 49%CRITICAL2012-03-08

Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0587, CVE-2012-0588, and CVE-2012-0589.

CVEs:CVE-2012-0586

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2012-0587

iOSEPSS <= 49%CRITICAL2012-03-08

Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0588, and CVE-2012-0589.

CVEs:CVE-2012-0587

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2012-0588

iOSEPSS <= 49%CRITICAL2012-03-08

Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0587, and CVE-2012-0589.

CVEs:CVE-2012-0588

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2012-0589

iOSEPSS <= 49%CRITICAL2012-03-08

Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0587, and CVE-2012-0588.

CVEs:CVE-2012-0589

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2011-3443

SafariEPSS <= 49%CRITICAL2012-03-02

Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors related to improper list management ...

CVEs:CVE-2011-3443

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-3059

OtherEPSS <= 49%HIGH2012-03-28

Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3059

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3053

OtherEPSS <= 49%CRITICAL2012-03-21

Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.

CVEs:CVE-2011-3053

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3058

OtherEPSS <= 49%CRITICAL2012-03-30

Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVEs:CVE-2011-3058

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2012-0584

SafariEPSS <= 49%MEDIUM2012-03-12

The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allows remote attackers to spoof a domain name via unspecified homoglyphs.

CVEs:CVE-2012-0584

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-3056

OtherEPSS <= 49%MEDIUM2012-03-21

Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."

CVEs:CVE-2011-3056

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2012-0647

SafariEPSS <= 49%MEDIUM2012-03-12

WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.

CVEs:CVE-2012-0647

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-0640

SafariEPSS <= 49%CRITICAL2012-03-12

WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remote web servers to track users via a cookie.

CVEs:CVE-2012-0640

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-3844

SafariEPSS <= 49%MEDIUM2012-03-08

Apple Safari 5.0.5 does not properly implement the setInterval function, which allows remote attackers to spoof the address bar via a crafted web page.

CVEs:CVE-2011-3844

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-0645

iOSEPSS <= 49%LOW2012-03-08

Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows physically proximate attackers to bypass the locked state via a command that forwards an active e-mail message to an arbitrary recipi...

CVEs:CVE-2012-0645

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2012-0644

iOSEPSS <= 49%MEDIUM2012-03-08

Race condition in the Passcode Lock feature in Apple iOS before 5.1 allows physically proximate attackers to bypass intended passcode requirements via a slide-to-dial gesture.

CVEs:CVE-2012-0644

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.