CVE-2011-3442
- EPSS 0.05%
- Veröffentlicht 11.11.2011 18:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a crafted app.
CVE-2011-3897
- EPSS 2.1%
- Veröffentlicht 11.11.2011 11:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
CVE-2011-3881
- EPSS 0.5%
- Veröffentlicht 25.10.2011 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selec...
CVE-2011-3885
- EPSS 2.41%
- Veröffentlicht 25.10.2011 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.
- EPSS 0.52%
- Veröffentlicht 25.10.2011 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
CVE-2011-3888
- EPSS 2.1%
- Veröffentlicht 25.10.2011 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown pl...
CVE-2011-2845
- EPSS 0.53%
- Veröffentlicht 25.10.2011 19:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
CVE-2011-3434
- EPSS 0.42%
- Veröffentlicht 14.10.2011 10:55:11
- Zuletzt bearbeitet 29.04.2026 01:13:23
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
CVE-2011-3256
- EPSS 3.24%
- Veröffentlicht 14.10.2011 10:55:10
- Zuletzt bearbeitet 29.04.2026 01:13:23
FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, ...
CVE-2011-3257
- EPSS 0.06%
- Veröffentlicht 14.10.2011 10:55:10
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a d...