Subscribe via feed.
Posts under OSX security tools

Safari 5.1 / 5.0.6 XSS / Code Execution / SSL Trust Issue

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-07-20-1 – A large amount of security issues have been addressed in Safari versions 5.1 and 5.0.6. These range from cross site scripting, possible arbitrary code execution, accidental trust in a disable root certificate, buffer and integer overflows, and more.

Tags: , , , ,

Secunia Security Advisory 45325

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – A weakness and multiple vulnerabilities have been reported in Apple Safari, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, and compromise a user’s system.

Tags: , , ,

Apple Security Advisory 2011-07-15-2

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-07-15-2 – A buffer overflow exists in FreeType’s handling of TrueType font files. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.

Tags: ,

Apple Security Advisory 2011-07-15-1

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-07-15-1 – A buffer overflow exists in FreeType’s handling of TrueType fonts. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution

Tags: , ,

Secunia Security Advisory 45224

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – A vulnerability has been reported in Apple iOS, which can be exploited by malicious people to compromise a vulnerable system.

Tags: , ,

Apple Security Advisory 2011-06-28-2

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-06-28-2 – Multiple vulnerabilities exist in Java 1.6.0_24, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user.

Tags: ,

Mac OS X 10.6.6 Camera Raw Library Memory Corruption

Posted by deepcore under Apple, OSX security tools (No Respond)

A corrupt Canon Camera RAW file (.CR2) can cause a crash in the RawCamera library. This affects viewing files in both the Preview.app application or via Quick Look. Mac OS X 10.6.6 with RawCamera.bundle versions prior to 3.6 are affected.

Tags: , , ,

Apple Mac OS X ImageIO TIFF Heap Overflow

Posted by deepcore under Apple, OSX security tools (No Respond)

Dominic Chell of NGS Secure has discovered a High risk vulnerability in Mac OS X ImageIO. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.

Tags: , ,

Apple Developer Cross Site Scripting / Redirect

Posted by deepcore under Apple, OSX security tools (No Respond)

The Apple Developer site suffered from open redirect, cross site scripting, and http response splitting vulnerabilities.

Tags: , , ,

Zero Day Initiative Advisory 11-231

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-231 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file

Tags: , ,