Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2012-09-13 CVE-2012-4904 Cross-Site Scripting vulnerability in Google Chrome
Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.
network
google CWE-79
4.3
2012-09-13 CVE-2012-4903 Permissions, Privileges, and Access Controls vulnerability in Google Chrome
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4906.
network
low complexity
google CWE-264
5.0
2012-09-13 CVE-2012-3712 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8
2012-09-13 CVE-2012-3711 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8
2012-09-13 CVE-2012-3710 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8
2012-09-13 CVE-2012-3709 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8
2012-09-13 CVE-2012-3708 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8
2012-09-13 CVE-2012-3707 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8
2012-09-13 CVE-2012-3706 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8
2012-09-13 CVE-2012-3705 Memory Corruption vulnerability in WebKit
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
network
apple
6.8