Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2011-03-11 CVE-2011-0160 Improper Input Validation vulnerability in Apple Iphone OS, Safari and Webkit
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
network
low complexity
apple CWE-20
5.0
2011-03-11 CVE-2011-0159 Improper Input Validation vulnerability in Apple Iphone OS 4.0/4.1/4.2
The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari application, which might make it easier for remote web servers to track users by setting a cookie.
network
low complexity
apple CWE-20
5.0
2011-03-11 CVE-2011-0158 Improper Input Validation vulnerability in Apple Iphone OS
MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL handlers, which allows remote attackers to cause a denial of service (persistent application crash) via crafted JavaScript code.
network
apple CWE-20
4.3
2011-03-11 CVE-2011-1417 Numeric Errors vulnerability in Apple Iphone OS, mac OS X and mac OS X Server
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
network
apple CWE-189
6.8
2011-03-11 CVE-2011-1204 Improper Input Validation vulnerability in Google Chrome
Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.
network
google apple CWE-20
6.8
2011-03-11 CVE-2011-1190 Information Exposure vulnerability in Google Chrome
The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
network
low complexity
google apple CWE-200
5.0
2011-03-10 CVE-2011-1344 Resource Management Errors vulnerability in Apple Safari
Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding children to a WBR tag and then removing the tag, related to text nodes, as demonstrated by Chaouki Bekrar during a Pwn2Own competition at CanSecWest 2011.
network
apple CWE-399
6.8
2011-03-03 CVE-2011-0154 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes
WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
network
high complexity
apple CWE-119
5.1
2011-03-02 CVE-2010-4754 Resource Management Errors vulnerability in multiple products
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.
network
low complexity
apple freebsd netbsd openbsd CWE-399
4.0
2011-03-01 CVE-2011-1107 Multiple Security vulnerability in Google Chrome prior to 9.0.597.107
Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.
network
google apple
4.3