CVE-2012-3703
published 2012-09-13CVE-2012-3703: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…
PriorityP434high8.3CVSS 2.0
AVNACMAuNCPIPAC
EPSS
2.66%
84.0th percentile
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | <= 10.6.3 | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
osv8.3HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vr74-3cr6-4g8x: WebKit, as used in Apple iTunes before 10
ghsa_unreviewed·2022-05-17
CVE-2012-3703 [HIGH] GHSA-vr74-3cr6-4g8x: WebKit, as used in Apple iTunes before 10
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
OSV
CVE-2012-3703: WebKit, as used in Apple iTunes before 10
osv·2012-09-13·CVSS 8.3
CVE-2012-3703 [HIGH] CVE-2012-3703: WebKit, as used in Apple iTunes before 10
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Red Hat
Neutron: security groups fail to block traffic properly due to packstack configuration
vendor_redhat·2014-10-22·CVSS 5.0
CVE-2014-3703 [MEDIUM] Neutron: security groups fail to block traffic properly due to packstack configuration
Neutron: security groups fail to block traffic properly due to packstack configuration
OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.
It was discovered that the nova.conf configuration generated by PackStack did not correctly set the libvirt_vif_driver configuration option if the Open vSwitch (OVS) monolithic plug-in was not used. This could result in deployments defaulting to having the firewall disabled unless the nova configuration was manually modified after PackStack was started.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00005.htmlhttp://osvdb.org/85386http://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5502http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/55534https://exchange.xforce.ibmcloud.com/vulnerabilities/78557https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17478http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00005.htmlhttp://osvdb.org/85386http://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5502http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/55534https://exchange.xforce.ibmcloud.com/vulnerabilities/78557https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17478
2012-09-13
Published