CVE-2011-3919
- EPSS 3.19%
- Veröffentlicht 07.01.2012 11:55:13
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
- EPSS 2.34%
- Veröffentlicht 13.12.2011 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
- EPSS 2.34%
- Veröffentlicht 13.12.2011 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, which allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
CVE-2011-3913
- EPSS 2.29%
- Veröffentlicht 13.12.2011 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to Range handling.
CVE-2011-3439
- EPSS 6.54%
- Veröffentlicht 11.11.2011 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.
CVE-2011-3440
- EPSS 0.06%
- Veröffentlicht 11.11.2011 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.
CVE-2011-3441
- EPSS 0.42%
- Veröffentlicht 11.11.2011 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.
CVE-2011-3442
- EPSS 0.05%
- Veröffentlicht 11.11.2011 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a crafted app.
CVE-2011-3897
- EPSS 2.1%
- Veröffentlicht 11.11.2011 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
CVE-2011-3881
- EPSS 0.5%
- Veröffentlicht 25.10.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selec...