Subscribe via feed.

Secunia Security Advisory 47319

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – A weakness has been discovered in Apple Safari, which can be exploited by malicious people to disclose sensitive information.

Tags: , ,

Apple Safari file:// Arbitrary Code Execution

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

This Metasploit module exploits a vulnerability found in Apple Safari on OSX platform. A policy issue in the handling of file:// URLs may allow arbitrary remote code execution under the context of the user. In order to trigger arbitrary remote code execution, the best way seems to be opening a share on the victim machine first (this can be SMB/WebDav/FTP, or a fileformat that OSX might automount), and then execute it in /Volumes/[share]

Tags: , ,

Apple Safari Arbitrary Code Execution

Posted by deepcore under Apple, OSX security tools (No Respond)

Apple Safari versions prior to 5.1.1 fail to enforce an intended policy for file:// URLs and in turn allows for remote attackers to execute code.

Tags: , , ,

Apple Safari Directory Traversal

Posted by deepcore under Apple, OSX security tools (No Respond)

Apple Safari versions 5.0 and later on Mac OS and Windows are vulnerable to a directory traversal issue with the handling of “safari-extension://” URLs. Attackers can create malicious websites that trigger Safari to send files from the victim’s system to the attacker. Arbitrary Javascript can be executed in the web context of the Safari extension.

Tags: , ,

Secunia Security Advisory 46412

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – A weakness and multiple vulnerabilities have been reported in Apple Safari, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, disclose potentially sensitive information, and compromise a user’s system.

Tags: , ,

Secunia Security Advisory 45325

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – A weakness and multiple vulnerabilities have been reported in Apple Safari, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, and compromise a user’s system.

Tags: , , ,

Zero Day Initiative Advisory 11-140

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-140 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari WebKit.

Tags: , ,

Secunia Security Advisory 42264

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – Multiple vulnerabilities and weaknesses have been reported in Apple Safari, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing attacks, or compromise a user’s system.

Tags: , ,