CVE-2011-3214
- EPSS 0.07%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.
CVE-2011-3215
- EPSS 0.07%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allows physically proximate attackers to bypass intended access restrictions and discover a password by making a DMA request in the (1)...
CVE-2011-3216
- EPSS 0.06%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.
CVE-2011-3217
- EPSS 1.41%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.
CVE-2011-3218
- EPSS 0.66%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing th...
CVE-2011-3220
- EPSS 0.74%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
CVE-2011-3221
- EPSS 1.77%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.
CVE-2011-3222
- EPSS 2.25%
- Veröffentlicht 14.10.2011 10:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
CVE-2011-0185
- EPSS 0.06%
- Veröffentlicht 14.10.2011 10:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.
CVE-2011-0224
- EPSS 1.41%
- Veröffentlicht 14.10.2011 10:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.