Vulnerabilities > Apple > Safari > 5.1

DATE CVE VULNERABILITY TITLE RISK
2012-02-16 CVE-2011-3027 Incorrect Type Conversion OR Cast vulnerability in Google Chrome
Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
network
google apple CWE-704
4.3
2012-02-16 CVE-2011-3021 USE After Free vulnerability in Google Chrome
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to subframe loading.
network
low complexity
google apple CWE-416
7.5
2012-02-16 CVE-2011-3016 USE After Free vulnerability in Google Chrome
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.
network
google apple CWE-416
6.8
2011-12-07 CVE-2011-4692 Permissions, Privileges, and Access Controls vulnerability in multiple products
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.
network
low complexity
apple google CWE-264
5.0
2011-10-14 CVE-2011-3243 Cross-Site Scripting vulnerability in Apple Iphone OS and Safari
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
network
apple CWE-79
4.3
2011-10-14 CVE-2011-3242 Information Exposure vulnerability in Apple Safari
The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of the Block Cookies setting, which makes it easier for remote web servers to track users via a cookie.
network
low complexity
apple CWE-200
5.0
2011-10-14 CVE-2011-3231 Code Injection vulnerability in Apple Safari
The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates, which allows remote web servers to execute arbitrary code via a crafted certificate.
network
apple CWE-94
6.8
2011-10-14 CVE-2011-3230 Permissions, Privileges, and Access Controls vulnerability in Apple Safari
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.
network
apple CWE-264
6.8
2011-10-14 CVE-2011-3229 Path Traversal vulnerability in Apple Safari
Directory traversal vulnerability in Apple Safari before 5.1.1 allows remote attackers to execute arbitrary JavaScript code, in a Safari Extensions context, via a crafted safari-extension: URL.
network
apple CWE-22
6.8
2011-09-19 CVE-2011-3234 Out-Of-Bounds Read vulnerability in Google Chrome
Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
network
low complexity
google apple CWE-125
5.0