Show filters
195 Total Results
Displaying 101-110 of 195
Sort by:
Attacker Value
Unknown

CVE-2011-3231

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates, which allows remote web servers to execute arbitrary code via a crafted certificate.
0
Attacker Value
Unknown

CVE-2011-0163

Disclosure Date: March 11, 2011 (last updated October 04, 2023)
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.
0
Attacker Value
Unknown

CVE-2011-0161

Disclosure Date: March 11, 2011 (last updated October 04, 2023)
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
0
Attacker Value
Unknown

CVE-2011-0160

Disclosure Date: March 11, 2011 (last updated October 04, 2023)
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
0
Attacker Value
Unknown

CVE-2011-1344

Disclosure Date: March 10, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding children to a WBR tag and then removing the tag, related to text nodes, as demonstrated by Chaouki Bekrar during a Pwn2Own competition at CanSecWest 2011.
0
Attacker Value
Unknown

CVE-2011-0132

Disclosure Date: March 03, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
0
Attacker Value
Unknown

CVE-2011-0115

Disclosure Date: March 03, 2011 (last updated October 04, 2023)
The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
0
Attacker Value
Unknown

CVE-2010-1806

Disclosure Date: September 10, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.
0
Attacker Value
Unknown

CVE-2010-1807

Disclosure Date: September 10, 2010 (last updated October 04, 2023)
WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation.
0
Attacker Value
Unknown

CVE-2010-1805

Disclosure Date: September 10, 2010 (last updated October 04, 2023)
Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded by Safari.
0