| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2011-0199 |
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 5.8 MEDIUM |
| CVE-2011-0198 |
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0197 |
App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-2009-5044 |
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file. Published: June 24, 2011; 4:55:01 PM -0400 |
V3.x:(not available) V2.0: 3.3 LOW |
| CVE-2011-2110 |
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011. Published: June 16, 2011; 7:55:02 PM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2011-2106 |
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. Published: June 16, 2011; 7:55:02 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2105 |
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted font data. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2104 |
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2011-2103 |
Adobe Reader and Acrobat 8.x before 8.3 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2102 |
Unspecified vulnerability in Adobe Reader and Acrobat before 10.1 on Windows and Mac OS X allows attackers to bypass intended access restrictions via unknown vectors. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2101 |
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows attackers to execute arbitrary code via a crafted document, related to a "cross document script execution vulnerability." Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2099 |
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2098. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2098 |
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2099. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2097 |
Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2094 and CVE-2011-2095. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2096 |
Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2095 |
Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2094 and CVE-2011-2097. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2094 |
Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2095 and CVE-2011-2097. Published: June 16, 2011; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-2107 |
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability." Published: June 08, 2011; 10:38:36 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2011-1783 |
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data. Published: June 06, 2011; 3:55:01 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2011-1752 |
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011. Published: June 06, 2011; 3:55:01 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |