CVE-2011-0163
published 2011-03-11CVE-2011-0163: WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.59%
73.2th percentile
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 4.2 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5ggv-2jrf-6fx5: WebKit, as used in Apple Safari before 5
ghsa_unreviewed·2022-05-17
CVE-2011-0163 [MEDIUM] CWE-20 GHSA-5ggv-2jrf-6fx5: WebKit, as used in Apple Safari before 5
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.
OSV
CVE-2011-0163: WebKit, as used in Apple Safari before 5
osv·2011-03-11·CVSS 4.3
CVE-2011-0163 [MEDIUM] CVE-2011-0163: WebKit, as used in Apple Safari before 5
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.
Red Hat
kernel: sctp: a race between ICMP protocol unreachable and connect()
vendor_redhat·2010-05-06·CVSS 7.1
CVE-2010-4526 [HIGH] CWE-662 kernel: sctp: a race between ICMP protocol unreachable and connect()
kernel: sctp: a race between ICMP protocol unreachable and connect()
Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list corruption, related to the sctp_wait_for_connect function.
Statement: The Linux kernel as shipped with Red Hat Enterprise Linux 4 did not include
upstream commit history:5aabd1fe268e850c2e93048a5ccc5eb6970ac49c, and therefore
is not affected by this issue. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via http://rhn.redhat.com/errata/RHSA-2011-0163.html, https://rhn.redhat.c
No detection rules found.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://support.apple.com/kb/HT4564http://support.apple.com/kb/HT4566http://www.securitytracker.com/id?1025182https://exchange.xforce.ibmcloud.com/vulnerabilities/66001http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://support.apple.com/kb/HT4564http://support.apple.com/kb/HT4566http://www.securitytracker.com/id?1025182https://exchange.xforce.ibmcloud.com/vulnerabilities/66001
2011-03-11
Published