| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2013-0970 |
Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirmation prompt via a crafted FaceTime: URL. Published: March 15, 2013; 4:55:10 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2013-0969 |
Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary System Preferences changes via unspecified use of the keyboard. Published: March 15, 2013; 4:55:10 PM -0400 |
V3.x:(not available) V2.0: 4.9 MEDIUM |
| CVE-2013-0967 |
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site. Published: March 15, 2013; 4:55:10 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2013-0966 |
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI. Published: March 15, 2013; 4:55:10 PM -0400 |
V3.x:(not available) V2.0: 6.4 MEDIUM |
| CVE-2013-1375 |
Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler before 3.6.0.6090 allows attackers to execute arbitrary code via unspecified vectors. Published: March 13, 2013; 12:55:02 PM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-1371 |
Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler before 3.6.0.6090 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. Published: March 13, 2013; 12:55:02 PM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-0650 |
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler before 3.6.0.6090 allows attackers to execute arbitrary code via unspecified vectors. Published: March 13, 2013; 12:55:02 PM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-0646 |
Integer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler before 3.6.0.6090 allows attackers to execute arbitrary code via unspecified vectors. Published: March 13, 2013; 12:55:02 PM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2013-1775 |
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch. Published: March 05, 2013; 4:38:56 PM -0500 |
V3.x:(not available) V2.0: 6.9 MEDIUM |
| CVE-2013-1124 |
The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during an SSL session, which allows man-in-the-middle attackers to spoof ISE servers via an arbitrary certificate, aka Bug ID CSCub24309. Published: February 28, 2013; 6:55:01 PM -0500 |
V3.x:(not available) V2.0: 5.8 MEDIUM |
| CVE-2013-2268 |
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue." Published: February 23, 2013; 4:55:02 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2013-0900 |
Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. Published: February 23, 2013; 4:55:02 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2013-0899 |
Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet. Published: February 23, 2013; 4:55:02 PM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2013-0898 |
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a URL. Published: February 23, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2013-0897 |
Off-by-one error in the PDF functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service via a crafted document. Published: February 23, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2013-0896 |
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly manage memory during message handling for plug-ins, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. Published: February 23, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2013-0895 |
Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which might make it easier for remote attackers to execute arbitrary programs via unspecified vectors. Published: February 23, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2013-0893 |
Race condition in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media. Published: February 23, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2013-0892 |
Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors. Published: February 23, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2013-0891 |
Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob. Published: February 23, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |