Apple Security Advisories · May 2013 — Apple Security Advisories
34 advisories 34 CVEs

Apple-vendor CVEs for 2013-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-1017

OtherWeaponized exploitHIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file.

CVEs:CVE-2013-1017

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-2842

OtherPoC exploitCRITICAL2013-05-22

Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.

CVEs:CVE-2013-2842

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2013-0992

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0992

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-1019

OtherPoC exploitHIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.

CVEs:CVE-2013-1019

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
quicktime affected apple
Upstream advisory

CVE-2013-0986

OtherPoC exploitHIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted enof atoms in a movie file.

CVEs:CVE-2013-0986

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
quicktime affected apple
Upstream advisory

CVE-2013-0988

OtherPoC exploitHIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FPX file.

CVEs:CVE-2013-0988

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-0989

OtherPoC exploitHIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP3 file.

CVEs:CVE-2013-0989

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-0987

OtherPoC exploitHIGH2013-05-24

Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QTIF file.

CVEs:CVE-2013-0987

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-1015

OtherPoC exploitHIGH2013-05-24

Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TeXML file.

CVEs:CVE-2013-1015

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-0997

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0997

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-0999

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0999

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1000

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1000

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1001

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1001

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1002

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1002

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1003

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1003

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1004

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1004

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1005

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1005

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1006

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1006

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1007

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1007

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1008

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1008

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-1010

SafariPoC exploitHIGH2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1010

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
Upstream advisory

CVE-2013-0994

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0994

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-0991

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0991

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-0993

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0993

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-0995

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0995

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-0996

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0996

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-0998

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-0998

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-1011

SafariPoC exploitCRITICAL2013-05-19

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability t...

CVEs:CVE-2013-1011

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2013-1018

OtherEPSS <= 49%HIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

CVEs:CVE-2013-1018

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-1022

OtherEPSS <= 49%HIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted mvhd atoms in a movie file.

CVEs:CVE-2013-1022

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-1016

OtherEPSS <= 49%HIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.263 encoding.

CVEs:CVE-2013-1016

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-1021

OtherEPSS <= 49%HIGH2013-05-24

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG data in a movie file.

CVEs:CVE-2013-1021

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-1020

OtherEPSS <= 49%HIGH2013-05-24

Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a movie file.

CVEs:CVE-2013-1020

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2013-1014

OtherEPSS <= 49%MEDIUM2013-05-19

Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.

CVEs:CVE-2013-1014

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.