Apple Security Advisories · July 2012 — Apple Security Advisories
78 advisories 78 CVEs

Apple-vendor CVEs for 2012-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2012-3604

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3604

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3625

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3625

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3626

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3626

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3628

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3628

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3645

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3645

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3655

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3655

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3656

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3656

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3669

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3669

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3670

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3670

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3674

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3674

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3680

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3680

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3611

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3611

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3627

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3627

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3678

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3678

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-0682

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-0682

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-0683

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-0683

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3591

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3591

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3593

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3593

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3594

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3594

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3595

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3595

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3596

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3596

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3603

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3603

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3605

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3605

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3608

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3608

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3609

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3609

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3610

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3610

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3620

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3620

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3633

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3633

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3635

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3635

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3640

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3640

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3642

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3642

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3644

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3644

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3646

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3646

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3661

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3661

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3663

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3663

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3679

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3679

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3682

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3682

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-1520

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-1520

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3589

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3589

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3592

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3592

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3597

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3597

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3599

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3599

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3600

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3600

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3618

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3618

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3629

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3629

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3631

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3631

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3634

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3634

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3636

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3636

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3638

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3638

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3639

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3639

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3641

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3641

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3653

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3653

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3664

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3664

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3665

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3665

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3667

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3667

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3668

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3668

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3681

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3681

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3686

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3686

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3615

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3615

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3630

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3630

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3637

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3637

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3666

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3666

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3683

SafariEPSS <= 49%HIGH2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3683

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3590

SafariEPSS <= 49%CRITICAL2012-07-25

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPL...

CVEs:CVE-2012-3590

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-1147

OtherEPSS <= 49%HIGH2012-07-03

readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.

CVEs:CVE-2012-1147

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2012-0680

SafariEPSS <= 49%CRITICAL2012-07-25

Apple Safari before 6.0 does not properly handle the autocomplete attribute of a password input element, which allows remote attackers to bypass authentication by leveraging an unattended workstation.

CVEs:CVE-2012-0680

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3697

SafariEPSS <= 49%HIGH2012-07-25

WebKit in Apple Safari before 6.0 does not properly handle file: URLs, which allows remote attackers to bypass intended sandbox restrictions and read arbitrary files by leveraging a WebProcess compromise.

CVEs:CVE-2012-3697

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-0679

SafariEPSS <= 49%HIGH2012-07-25

Apple Safari before 6.0 allows remote attackers to read arbitrary files via a feed:// URL.

CVEs:CVE-2012-0679

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3689

SafariEPSS <= 49%MEDIUM2012-07-25

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.

CVEs:CVE-2012-3689

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3693

SafariEPSS <= 49%MEDIUM2012-07-25

Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, by leveraging the availability of IDN support and Unicode fonts to construct unspecifi...

CVEs:CVE-2012-3693

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3698

XcodeEPSS <= 49%MEDIUM2012-07-26

Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonstrated by the keychain entries of...

CVEs:CVE-2012-3698

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2012-3695

SafariEPSS <= 49%CRITICAL2012-07-25

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML by leveraging improper URL canonicalization during the handling of the location.href property.

CVEs:CVE-2012-3695

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3691

SafariEPSS <= 49%MEDIUM2012-07-25

WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

CVEs:CVE-2012-3691

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3650

SafariEPSS <= 49%HIGH2012-07-25

WebKit in Apple Safari before 6.0 accesses uninitialized memory locations during the rendering of SVG images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

CVEs:CVE-2012-3650

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3696

SafariEPSS <= 49%MEDIUM2012-07-25

CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSockets URI handling.

CVEs:CVE-2012-3696

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-0678

SafariEPSS <= 49%CRITICAL2012-07-25

Cross-site scripting (XSS) vulnerability in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML via a feed:// URL.

CVEs:CVE-2012-0678

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3690

SafariEPSS <= 49%HIGH2012-07-25

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to read arbitrary files via a crafted web site.

CVEs:CVE-2012-3690

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2012-3694

SafariEPSS <= 49%HIGH2012-07-25

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to obtain sensitive information about full pathnames via a crafted web site.

CVEs:CVE-2012-3694

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.