Apple Security Advisories · December 2013 — Apple Security Advisories
11 advisories 11 CVEs

Apple-vendor CVEs for 2013-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-6420

OtherWeaponized exploitCRITICAL2013-12-09

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execut...

CVEs:CVE-2013-6420

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2012-6151

OtherPoC exploitHIGH2013-12-13

Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, and hang) by causing the AgentX subagent to timeout.

CVEs:CVE-2012-6151

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2013-5227

SafariPoC exploitMEDIUM2013-12-17

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.

CVEs:CVE-2013-5227

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2013-5199

SafariEPSS <= 49%CRITICAL2013-12-17

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2013-5199

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
webkit affected apple
Upstream advisory

CVE-2013-5198

SafariEPSS <= 49%CRITICAL2013-12-17

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2013-5198

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
webkit affected apple
Upstream advisory

CVE-2013-5228

SafariEPSS <= 49%CRITICAL2013-12-17

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2013-5228

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
webkit affected apple
Upstream advisory

CVE-2013-5196

SafariEPSS <= 49%CRITICAL2013-12-17

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2013-5196

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
webkit affected apple
Upstream advisory

CVE-2013-5197

SafariEPSS <= 49%CRITICAL2013-12-17

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2013-5197

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
webkit affected apple
Upstream advisory

CVE-2013-5225

SafariEPSS <= 49%CRITICAL2013-12-17

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2013-5225

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
webkit affected apple
Upstream advisory

CVE-2013-5195

SafariEPSS <= 49%CRITICAL2013-12-17

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other Web...

CVEs:CVE-2013-5195

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2013-7127

macOSEPSS <= 49%MEDIUM2013-12-17

Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.

CVEs:CVE-2013-7127

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.