Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.5
CVE-2011-3446

Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execu…

Fix: after 10.7.2
Fix from $1,950 2012-02-02
Mac Os X HIGH 7.5
CVE-2011-3453

Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap me…

Fix: after 10.7.2
Fix from $1,950 2012-02-02
Mac Os X HIGH 7.5
CVE-2011-3457

The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remo…

Fix: after 10.7.2
Fix from $1,950 2012-02-02
Mac Os X HIGH 7.5
CVE-2011-3460

Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (applicat…

Fix: after 10.7.2
Fix from $1,950 2012-02-02
Mac Os X HIGH 7.2
CVE-2011-3463

WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by levera…

Mitigation only
Fix from $1,950 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3448

Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of servic…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3449

Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of servi…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3450

CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arb…

Mitigation only
Fix from $1,600 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3458

QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitra…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3459

Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (applica…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Mac Os X MEDIUM 5.0
CVE-2011-3462

Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote atta…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Safari MEDIUM 5.0
CVE-2011-4692

WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for imag…

Fix: after 15
Fix from $1,600 2011-12-07
Safari MEDIUM 5.0
CVE-2010-5070

The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle…

No fix yet
Fix from $1,600 2011-12-07
Mac Os X HIGH 7.6
CVE-2008-7303

The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attack…

No fix yet
Fix from $1,950 2011-11-15
Mac Os X HIGH 7.6
CVE-2011-1516

The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all crea…

No fix yet
Fix from $1,950 2011-11-15
Iphone Os HIGH 9.3
CVE-2011-3439EPSS 5%

FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…

Fix: 5.0.1+
Fix from $1,950 2011-11-11
Iphone Os HIGH 7.2
CVE-2011-3442

The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute a…

Mitigation only
Fix from $1,950 2011-11-11
Mac Os X MEDIUM 6.8
CVE-2011-3437

Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a cr…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.5
CVE-2011-3436

Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allo…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os HIGH 9.3
CVE-2011-3430

The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement local…

No fix yet
Fix from $1,950 2011-10-14
Iphone Os MEDIUM 6.8
CVE-2011-3260

Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application cra…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os MEDIUM 6.8
CVE-2011-3261

Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (appli…

Mitigation only
Fix from $1,600 2011-10-14
Apple Tv MEDIUM 5.0
CVE-2011-3259

The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remo…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os MEDIUM 5.0
CVE-2011-3432

The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3223

Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (applicat…

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3226

Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypas…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3227

libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation …

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3228

QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and appli…

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Safari MEDIUM 6.8
CVE-2011-3229

Directory traversal vulnerability in Apple Safari before 5.1.1 allows remote attackers to execute arbitrary JavaScript code, in a Safari Extensions c…

Fix: after 5.1
Fix from $1,600 2011-10-14
Safari MEDIUM 6.8
CVE-2011-3230EPSS 50%

Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via…

Fix: after 5.1
Fix from $1,600 2011-10-14