CVE-2011-3231Code Injection in Apple Safari

CWE-94Code Injection2 documents2 sources
Severity
6.8MEDIUMNVD
EPSS
0.5%
top 36.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 14
Latest updateMay 17

Description

The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates, which allows remote web servers to execute arbitrary code via a crafted certificate.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDapple/safari5.1+70

🔴Vulnerability Details

1
GHSA
GHSA-5x4w-6r2x-m2rf: The SSL implementation in Apple Safari before 52022-05-17