Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2011-0219

около 15 лет назад

Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-0218

около 15 лет назад

WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-0217

около 15 лет назад

Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-0216

около 15 лет назад

Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-0215

около 15 лет назад

ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-0214

около 15 лет назад

CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-0213

около 15 лет назад

Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG file.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0212

около 15 лет назад

servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2011-0211

около 15 лет назад

Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0210

около 15 лет назад

QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0209

около 15 лет назад

Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0208

около 15 лет назад

QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0207

около 15 лет назад

The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-0206

около 15 лет назад

Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-0205

около 15 лет назад

Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0204

около 15 лет назад

Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0203

около 15 лет назад

Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-0202

около 15 лет назад

Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-0201

около 15 лет назад

Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-0200

около 15 лет назад

Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-0219

Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.

CVSS2: 5.8
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0218

WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

CVSS2: 9.3
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0217

Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.

CVSS2: 4.3
1%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0216

Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.

CVSS2: 9.3
5%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0215

ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file.

CVSS2: 9.3
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0214

CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.

CVSS2: 5
1%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0213

Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG file.

CVSS2: 6.8
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0212

servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.

CVSS2: 6.4
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0211

Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

CVSS2: 6.8
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0210

QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.

CVSS2: 6.8
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0209

Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.

CVSS2: 6.8
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0208

QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.

CVSS2: 6.8
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0207

The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network.

CVSS2: 5
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0206

Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.

CVSS2: 7.5
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0205

Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.

CVSS2: 6.8
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0204

Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image.

CVSS2: 6.8
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0203

Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.

CVSS2: 5
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0202

Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.

CVSS2: 6.8
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0201

Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.

CVSS2: 7.5
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0200

Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.

CVSS2: 6.8
4%
Низкий
около 15 лет назад

Уязвимостей на страницу