Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2012-02-02 CVE-2011-3444 Cryptographic Issues vulnerability in Apple mac OS X and mac OS X Server
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.
network
apple CWE-310
4.3
2011-12-21 CVE-2011-3666 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Thunderbird
Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file.
6.8
2011-12-21 CVE-2011-3664 NULL Pointer Dereference Denial Of Service vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
network
mozilla apple
6.8
2011-12-07 CVE-2011-4692 Permissions, Privileges, and Access Controls vulnerability in multiple products
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.
network
low complexity
apple google CWE-264
5.0
2011-12-07 CVE-2010-5070 Permissions, Privileges, and Access Controls vulnerability in Apple Safari
The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264.
network
low complexity
apple CWE-264
5.0
2011-11-11 CVE-2011-3441 Information Exposure vulnerability in Apple Iphone OS
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.
network
apple CWE-200
4.3
2011-11-09 CVE-2011-3998 Cross-Site Scripting vulnerability in Apple Webobjects
Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
apple CWE-79
4.3
2011-11-09 CVE-2011-3653 Information Exposure vulnerability in Mozilla Firefox and Thunderbird
Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.
network
low complexity
mozilla apple CWE-200
5.0
2011-10-14 CVE-2011-3437 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.
network
apple CWE-189
6.8
2011-10-14 CVE-2011-3436 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.
network
low complexity
apple CWE-264
6.5