CVE-2011-0170
published 2011-03-03CVE-2011-0170: Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.76%
90.9th percentile
Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile in a JPEG image.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | <= 10.1.2 | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p55r-97rj-vp52: Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10
ghsa_unreviewed·2022-05-17
CVE-2011-0170 [HIGH] CWE-119 GHSA-p55r-97rj-vp52: Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10
Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile in a JPEG image.
Red Hat
Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)
vendor_redhat·2011-09-28·CVSS 4.3
CVE-2011-2999 [MEDIUM] CWE-79 Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)
Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)
Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=897http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4566http://support.apple.com/kb/HT4581https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17367http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=897http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4566http://support.apple.com/kb/HT4581https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17367
2011-03-03
Published