Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cristian Draghici

Researcher fromModulo Consulting
#18827of 53,633
14.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2011-2181
7.5
2011-06-24
Apple · Macos X · CVE-2011-0201
**Name of the Vulnerable Software and Affected Versions** Apple Mac OS X versions prior to 10.6.8 **Description** The issue is related to an off-by-one error in the CoreFoundation framework, which can be exploited by context-dependent attackers to execute arbitrary code or cause a denial of service, resulting in an application crash. This is achieved through a CFString object that triggers a buffer overflow. **Recommendations** For Apple Mac OS X versions prior to 10.6.8, update to version 10.6.8 or later to resolve the issue.
PT-2011-2182
6.8
2011-06-24
Apple · Coregraphics · CVE-2011-0202
**Name of the Vulnerable Software and Affected Versions** Apple Mac OS X versions prior to 10.6.8 **Description** The issue is related to an integer overflow in CoreGraphics, which can be triggered by a crafted embedded Type 1 font in a PDF document. This can allow remote attackers to execute arbitrary code or cause a denial of service, resulting in an application crash. **Recommendations** For versions prior to 10.6.8, update to version 10.6.8 or later to resolve the issue.