Subscribe via feed.

Secunia Security Advisory 45325

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – A weakness and multiple vulnerabilities have been reported in Apple Safari, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, and compromise a user’s system.

Tags: , , ,

Apple Security Advisory 2011-07-15-1

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-07-15-1 – A buffer overflow exists in FreeType’s handling of TrueType fonts. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution

Tags: , ,

Secunia Security Advisory 45224

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – A vulnerability has been reported in Apple iOS, which can be exploited by malicious people to compromise a vulnerable system.

Tags: , ,

Apple Developer Cross Site Scripting / Redirect

Posted by deepcore under Apple, OSX security tools (No Respond)

The Apple Developer site suffered from open redirect, cross site scripting, and http response splitting vulnerabilities.

Tags: , , ,

Zero Day Initiative Advisory 11-231

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-231 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file

Tags: , ,

Zero Day Initiative Advisory 11-230

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-230 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Quicktime handles Apple Lossless Audio Codec streams.

Tags: , , ,

Zero Day Initiative Advisory 11-229

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-229 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within how the application parses a specially formatted RIFF WAV file

Tags: , , , ,

Apple Security Advisory 2011-06-28

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-06-28-1 – Multiple vulnerabilities exist in Java 1.6.0_24, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating to Java version 1.6.0_26.

Tags: , ,

Secunia Security Advisory 45084

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – Apple has issued an update for Java for Mac OS X. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.

Tags: ,

Secunia Security Advisory 45054

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Secunia Security Advisory – Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.

Tags: , ,