CVE-2012-3659
published 2012-09-13CVE-2012-3659: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.72%
84.4th percentile
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | <= 10.6.3 | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j89g-39g2-m3qj: WebKit, as used in Apple iTunes before 10
ghsa_unreviewed·2022-05-17
CVE-2012-3659 [MEDIUM] GHSA-j89g-39g2-m3qj: WebKit, as used in Apple iTunes before 10
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
OSV
CVE-2012-3659: WebKit, as used in Apple iTunes before 10
osv·2012-09-13·CVSS 6.8
CVE-2012-3659 [MEDIUM] CVE-2012-3659: WebKit, as used in Apple iTunes before 10
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Red Hat
Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
vendor_redhat·2012-01-31·CVSS 9.3
CVE-2011-3659 [CRITICAL] Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00005.htmlhttp://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5502http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/55534https://exchange.xforce.ibmcloud.com/vulnerabilities/78515https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17562http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00005.htmlhttp://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5502http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/55534https://exchange.xforce.ibmcloud.com/vulnerabilities/78515https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17562
2012-09-13
Published