CVE-2011-0229
- EPSS 1.86%
- Published 14.10.2011 10:55:07
- Last modified 11.04.2025 00:51:21
Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access.
CVE-2011-2834
- EPSS 3.75%
- Published 19.09.2011 12:02:55
- Last modified 11.04.2025 00:51:21
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
CVE-2011-3422
- EPSS 0.38%
- Published 12.09.2011 12:40:44
- Last modified 11.04.2025 00:51:21
The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Ext...
CVE-2011-2821
- EPSS 2.28%
- Published 29.08.2011 15:55:01
- Last modified 11.04.2025 00:51:21
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
CVE-2011-2192
- EPSS 1.51%
- Published 07.07.2011 21:55:02
- Last modified 11.04.2025 00:51:21
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSS...
CVE-2011-2601
- EPSS 0.43%
- Published 30.06.2011 15:55:04
- Last modified 11.04.2025 00:51:21
The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desktop hang) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstr...
CVE-2009-5078
- EPSS 1.32%
- Published 30.06.2011 15:55:01
- Last modified 11.04.2025 00:51:21
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
CVE-2011-0197
- EPSS 0.05%
- Published 24.06.2011 20:55:02
- Last modified 11.04.2025 00:51:21
App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.
CVE-2011-0198
- EPSS 11.35%
- Published 24.06.2011 20:55:02
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font.
CVE-2011-0199
- EPSS 0.17%
- Published 24.06.2011 20:55:02
- Last modified 11.04.2025 00:51:21
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked cer...