Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kimyok

Researcher fromTencent Security Platform Department
#17165of 53,632
15.6Total CVSS
Vulnerabilities · 2
High
2
PT-2017-1678
7.8
2017-04-02
Apple · Apple Macos · CVE-2017-2431
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.12.4 **Description** The issue involves the CoreMedia component and allows remote attackers to execute arbitrary code or cause a denial of service, resulting in memory corruption and application crash, via a crafted .mov file. This is caused by a buffer overflow in memory. **Recommendations** For macOS versions prior to 10.12.4, update to version 10.12.4 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted .mov files to minimize the risk of exploitation.
PT-2017-1768
7.8
2017-04-02
Apple · Apple Macos · CVE-2017-2425
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.12.4 **Description** The issue involves the `SecurityFoundation` component and is related to a double free vulnerability. This vulnerability allows remote attackers to execute arbitrary code via a crafted certificate. **Recommendations** For macOS versions prior to 10.12.4, update to version 10.12.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `SecurityFoundation` component until a patch is available. Avoid using specially crafted certificates in the affected component to minimize the risk of exploitation.