Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2011-07-21 CVE-2011-0219 Permissions, Privileges, and Access Controls vulnerability in Apple Safari and Webkit
Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.
5.8
2011-07-21 CVE-2011-0217 Information Exposure vulnerability in Apple Safari
Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.
4.3
2011-07-21 CVE-2011-0214 Cryptographic Issues vulnerability in Apple Cfnetwork and Safari
CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.
network
low complexity
apple microsoft CWE-310
5.0
2011-07-21 CVE-2010-1420 Cross-Site Scripting vulnerability in Apple Cfnetwork and Safari
Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file.
4.3
2011-07-07 CVE-2011-2192 Credentials Management vulnerability in multiple products
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
4.3
2011-06-30 CVE-2009-5078 7PK - Security Features vulnerability in multiple products
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
network
low complexity
gnu apple CWE-254
6.4
2011-06-24 CVE-2011-1132 Denial of Service vulnerability in Apple Mac OS X IPV6 Socket Options (CVE-2010-1132)
The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.
local
low complexity
apple
4.9
2011-06-24 CVE-2011-0212 Resource Management Errors vulnerability in Apple mac OS X Server
servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
network
low complexity
apple CWE-399
6.4
2011-06-24 CVE-2011-0211 Numeric Errors vulnerability in Apple mac OS X, mac OS X Server and Quicktime
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
network
apple CWE-189
6.8
2011-06-24 CVE-2011-0210 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X, mac OS X Server and Quicktime
QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.
network
apple CWE-119
6.8