Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2011-11-09 CVE-2011-3998 Cross-Site Scripting vulnerability in Apple Webobjects
Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
apple CWE-79
4.3
2011-11-09 CVE-2011-3653 Information Exposure vulnerability in Mozilla Firefox and Thunderbird
Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.
network
low complexity
mozilla apple CWE-200
5.0
2011-10-28 CVE-2011-3251 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file.
network
apple microsoft CWE-119
critical
9.3
2011-10-28 CVE-2011-3250 Numeric Errors vulnerability in Apple Quicktime
Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.
network
apple microsoft CWE-189
critical
9.3
2011-10-28 CVE-2011-3249 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with FLC encoding.
network
apple microsoft CWE-119
critical
9.3
2011-10-28 CVE-2011-3248 Numeric Errors vulnerability in Apple Quicktime
Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file.
network
apple microsoft CWE-189
critical
9.3
2011-10-28 CVE-2011-3247 Numeric Errors vulnerability in Apple Quicktime
Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT file.
network
apple microsoft CWE-189
critical
9.3
2011-10-14 CVE-2011-3437 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
network
apple CWE-189
6.8
2011-10-14 CVE-2011-3436 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.
network
low complexity
apple CWE-264
6.5
2011-10-14 CVE-2011-3435 Credentials Management vulnerability in Apple mac OS X and mac OS X Server
Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.
local
low complexity
apple CWE-255
2.1