| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2010-3804 |
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171. Published: November 22, 2010; 8:00:17 AM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2010-3803 |
Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string. Published: November 22, 2010; 8:00:17 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2010-4008 |
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document. Published: November 16, 2010; 8:00:02 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2010-3798 |
Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3796 |
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2010-3795 |
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3794 |
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3793 |
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3792 |
Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3791 |
Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3790 |
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file that causes an image sample transformation to scale a sprite outside a buffer boundary. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3789 |
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted AVI file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3788 |
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3787 |
Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3786 |
QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Excel file. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3785 |
Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document. Published: November 16, 2010; 5:00:16 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-3784 |
The PMPageFormatCreateWithDataRepresentation API in Printing in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle XML data, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified API calls. Published: November 16, 2010; 5:00:15 PM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2010-1847 |
The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors. Published: November 16, 2010; 5:00:15 PM -0500 |
V3.x:(not available) V2.0: 4.9 MEDIUM |
| CVE-2010-1846 |
Heap-based buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RAW image. Published: November 16, 2010; 5:00:15 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2010-1845 |
ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image. Published: November 16, 2010; 5:00:15 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |