Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2011-07-21 CVE-2010-1420 Cross-Site Scripting vulnerability in Apple Cfnetwork and Safari
Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file.
4.3
2011-07-21 CVE-2010-1383 Credentials Management vulnerability in Apple Cfnetwork and Safari
CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.
network
apple microsoft CWE-255
critical
9.3
2011-07-19 CVE-2011-0227 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
The queueing primitives in IOMobileFrameBuffer in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 do not properly perform type conversion, which allows local users to gain privileges via a crafted application.
local
low complexity
apple CWE-264
7.2
2011-07-19 CVE-2011-0226 Numeric Errors vulnerability in multiple products
Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.
network
freetype apple CWE-189
critical
9.3
2011-07-07 CVE-2011-2192 Credentials Management vulnerability in multiple products
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
4.3
2011-06-30 CVE-2011-2603 Resource Management Errors vulnerability in Nvidia 9400M Driver 6.2.6
The NVIDIA 9400M driver 6.2.6 on Mac OS X 10.6.7 allows remote attackers to cause a denial of service (desktop hang) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.
network
nvidia apple CWE-399
7.1
2011-06-30 CVE-2011-2601 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desktop hang) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by using Mozilla Firefox or Google Chrome to visit the lots-of-polys-example.html test page in the Khronos WebGL SDK.
network
apple CWE-264
7.1
2011-06-30 CVE-2009-5078 7PK - Security Features vulnerability in multiple products
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
network
low complexity
gnu apple CWE-254
6.4
2011-06-24 CVE-2011-1132 Denial of Service vulnerability in Apple Mac OS X IPV6 Socket Options (CVE-2010-1132)
The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.
local
low complexity
apple
4.9
2011-06-24 CVE-2011-0212 Resource Management Errors vulnerability in Apple mac OS X Server
servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
network
low complexity
apple CWE-399
6.4