CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2011-0224

    Last Modified: 11 Apr 2025

    CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.

    Published: 14 Oct 2011
    2.6
    Low

    CVE-2011-3218

    Last Modified: 11 Apr 2025

    The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3223

    Last Modified: 11 Apr 2025

    Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.

    Published: 14 Oct 2011
    4.3
    Medium

    CVE-2011-3255

    Last Modified: 11 Apr 2025

    CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3437

    Last Modified: 11 Apr 2025

    Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.

    Published: 14 Oct 2011
    7.6
    High

    CVE-2011-0259

    Last Modified: 11 Apr 2025

    CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2341

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2352

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2356

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2811

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2813

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2814

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2817

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2820

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3233

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3235

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3236

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3237

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3238

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3239

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3244

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-3252

    Last Modified: 11 Apr 2025

    Buffer overflow in CoreAudio, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Advanced Audio Coding (AAC) stream.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2354

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2809

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2816

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-3219

    Last Modified: 11 Apr 2025

    Buffer overflow in CoreMedia, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2338

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2339

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2815

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-2831

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.6
    High

    CVE-2011-3241

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

    Published: 12 Oct 2011
    7.2
    High

    CVE-2011-2011

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-2009

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Windows Media Center in Microsoft Windows Vista SP2 and Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista, allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Media Center Insecure Library Loading Vulnerability."

    Published: 12 Oct 2011
    4.3
    Medium

    CVE-2011-1895

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."

    Published: 12 Oct 2011
    4.3
    Medium

    CVE-2011-1896

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1995

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1996

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1997

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnLoad Event Remote Code Execution Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1998

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "Jscript9.dll Remote Code Execution Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1999

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."

    Published: 12 Oct 2011
    4.7
    Medium

    CVE-2011-2002

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."

    Published: 12 Oct 2011
    5
    Medium

    CVE-2011-2007

    Last Modified: 11 Apr 2025

    Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."

    Published: 12 Oct 2011
    5
    Medium

    CVE-2011-2012

    Last Modified: 11 Apr 2025

    Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1969

    Last Modified: 11 Apr 2025

    Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-2001

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual Function Table Corruption Remote Code Execution Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-2003

    Last Modified: 11 Apr 2025

    Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."

    Published: 12 Oct 2011
    6.4
    Medium

    CVE-2011-3155

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Onboard Administrator (OA) 3.21 through 3.31 allows remote attackers to bypass intended access restrictions via unknown vectors.

    Published: 12 Oct 2011
    7.8
    High

    CVE-2011-2005

    Last Modified: 22 Apr 2026

    afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1247

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the Microsoft Active Accessibility component in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Active Accessibility Insecure Library Loading Vulnerability."

    Published: 12 Oct 2011
    9.3
    Critical

    CVE-2011-1253

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."

    Published: 12 Oct 2011