Show filters
149 Total Results
Displaying 31-40 of 149
Sort by:
Attacker Value
Unknown

CVE-2011-3228

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.
0
Attacker Value
Unknown

CVE-2011-3218

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
0
Attacker Value
Unknown

CVE-2011-3216

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.
0
Attacker Value
Unknown

CVE-2011-0231

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."
0
Attacker Value
Unknown

CVE-2011-3227

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
0
Attacker Value
Unknown

CVE-2011-0185

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.
0
Attacker Value
Unknown

CVE-2011-3214

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-3213

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.
0
Attacker Value
Unknown

CVE-2011-3222

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
0
Attacker Value
Unknown

CVE-2011-3422

Disclosure Date: September 12, 2011 (last updated October 04, 2023)
The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.
0