| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2011-2134 |
Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2137, CVE-2011-2414, and CVE-2011-2415. Published: August 10, 2011; 5:55:02 PM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2011-2130 |
Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2134, CVE-2011-2137, CVE-2011-2414, and CVE-2011-2415. Published: August 10, 2011; 5:55:02 PM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2011-2192 |
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests. Published: July 07, 2011; 5:55:02 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2011-2601 |
The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desktop hang) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by using Mozilla Firefox or Google Chrome to visit the lots-of-polys-example.html test page in the Khronos WebGL SDK. Published: June 30, 2011; 11:55:04 AM -0400 |
V3.x:(not available) V2.0: 7.1 HIGH |
| CVE-2009-5078 |
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document. Published: June 30, 2011; 11:55:01 AM -0400 |
V3.0: 6.5 MEDIUM V2.0: 6.4 MEDIUM |
| CVE-2011-1132 |
The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 4.9 MEDIUM |
| CVE-2011-0213 |
Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG file. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0211 |
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0210 |
QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0209 |
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0208 |
QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0207 |
The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2011-0206 |
Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2011-0205 |
Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0204 |
Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0202 |
Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0201 |
Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2011-0200 |
Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2011-0199 |
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 5.8 MEDIUM |
| CVE-2011-0198 |
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font. Published: June 24, 2011; 4:55:02 PM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |