Zero Day Initiative Advisory 12-137 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Mac OSX. Authentication is not required to exploit this vulnerability. The flaw exists within the libsecurity_cdsa_plugin which implements routines defined in libsecurity_cssm.

Zero Day Initiative Advisory 12-136 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple’s QuickTime player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page