CVE-2010-1383
- EPSS 0.56%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.
CVE-2010-1420
- EPSS 0.18%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file.
- EPSS 0.11%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certificatio...
CVE-2011-0215
- EPSS 1.75%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file.
CVE-2011-0216
- EPSS 2.96%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.
CVE-2011-0217
- EPSS 0.18%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fiel...
CVE-2011-0218
- EPSS 3%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in ...
CVE-2011-0219
- EPSS 0.13%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.
CVE-2011-0221
- EPSS 3%
- Veröffentlicht 21.07.2011 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in ...
CVE-2011-2351
- EPSS 2.01%
- Veröffentlicht 29.06.2011 17:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.