Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-03-15 CVE-2013-0966 Authentication Bypass vulnerability in Apple Mac OS X
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.
network
low complexity
apple
6.4
2013-03-15 CVE-2013-0961 Memory Corruption vulnerability in WebKit
WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0960.
network
apple
6.8
2013-03-15 CVE-2013-0960 Memory Corruption vulnerability in WebKit
WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0961.
network
apple
6.8
2013-03-05 CVE-2013-1775 Permissions, Privileges, and Access Controls vulnerability in multiple products
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
6.9
2013-02-28 CVE-2013-1124 Cryptographic Issues vulnerability in Cisco Network Admission Control
The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during an SSL session, which allows man-in-the-middle attackers to spoof ISE servers via an arbitrary certificate, aka Bug ID CSCub24309.
network
cisco apple CWE-310
5.8
2013-02-12 CVE-2013-0637 Information Exposure vulnerability in Adobe Air, AIR SDK and Flash Player
Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allow attackers to obtain sensitive information via unspecified vectors.
network
low complexity
adobe microsoft linux google apple CWE-200
5.0
2013-01-29 CVE-2013-0974 Security Bypass vulnerability in Apple iPhone/iPad/iPod touch
StoreKit in Apple iOS before 6.1 does not properly handle the disabling of JavaScript within the preferences configuration of Mobile Safari, which allows remote attackers to bypass intended access restrictions and execute JavaScript code via a web site with a Smart App Banner.
network
high complexity
apple
5.1
2013-01-29 CVE-2013-0968 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0959 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0958 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8