Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Binaryproof

Researcher fromTippingPoint's Zero Day Initiative
#21122of 53,611
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2011-2194
5.0
2011-07-21
Apple · Safari · CVE-2011-0214
**Name of the Vulnerable Software and Affected Versions** Apple Safari versions prior to 5.0.6 on Windows **Description** The issue arises from CFNetwork in Apple Safari not properly handling an untrusted attribute of a system root certificate. This allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority. **Recommendations** For Apple Safari versions prior to 5.0.6 on Windows, update to version 5.0.6 or later to resolve the issue.
PT-2011-2180
6.8
2011-06-24
Apple · Macos X · CVE-2011-0200
**Name of the Vulnerable Software and Affected Versions** Apple Mac OS X versions prior to 10.6.8 **Description** The issue is related to an integer overflow in ColorSync, which can be triggered by an image containing a crafted embedded ColorSync profile. This can lead to a heap-based buffer overflow, allowing remote attackers to execute arbitrary code or cause a denial of service, resulting in an application crash. **Recommendations** For Apple Mac OS X versions prior to 10.6.8, update to version 10.6.8 or later to resolve the issue. As a temporary workaround, consider avoiding the use of images with embedded ColorSync profiles until the update is applied.