CVE-2011-3236
published 2011-10-12CVE-2011-3236: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and…
PriorityP433high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
2.68%
84.1th percentile
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | <= 10.4.1 | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qfv6-fmj8-8hgg: WebKit, as used in Apple iTunes before 10
ghsa_unreviewed·2022-05-17
CVE-2011-3236 [HIGH] CWE-119 GHSA-qfv6-fmj8-8hgg: WebKit, as used in Apple iTunes before 10
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
OSV
CVE-2011-3236: WebKit, as used in Apple iTunes before 10
osv·2011-10-12·CVSS 7.6
CVE-2011-3236 [HIGH] CVE-2011-3236: WebKit, as used in Apple iTunes before 10
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.htmlhttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.htmlhttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00004.htmlhttp://osvdb.org/76350http://support.apple.com/kb/HT4981http://support.apple.com/kb/HT4999http://support.apple.com/kb/HT5000http://www.securityfocus.com/bid/50066https://exchange.xforce.ibmcloud.com/vulnerabilities/70513https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16714http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.htmlhttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.htmlhttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00004.htmlhttp://osvdb.org/76350http://support.apple.com/kb/HT4981http://support.apple.com/kb/HT4999http://support.apple.com/kb/HT5000http://www.securityfocus.com/bid/50066https://exchange.xforce.ibmcloud.com/vulnerabilities/70513https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16714
2011-10-12
Published