9.3
CVSSv2

CVE-2011-0216

Published: 21/07/2011 Updated: 07/02/2013
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Off-by-one error in libxml in Apple Safari prior to 5.0.6 allows remote malicious users to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 2.0.1

apple safari 1.2.2

apple safari 2.0.2

apple safari 1.0

apple safari 1.0.3

apple safari 1.0.2

apple safari 1.0.0

apple safari 2.0.3

apple safari 2.0.4

apple safari 2.0

apple safari 1.1

apple safari 3.2.1

apple safari 3.1.0

apple safari 3.0.4b

apple safari 1.2.0

apple safari 1.2.1

apple safari 1.2.5

apple safari 1.3

apple safari 3.0

apple safari 3.0.3

apple safari 5.0

apple safari 1.3.2

apple safari 4.1

apple safari 5.0.2

apple safari 3.0.2

apple safari 3.0.4

apple safari 1.3.1

apple safari 1.2.4

apple safari 1.1.1

apple safari 1.1.0

apple safari 1.0.1

apple safari 5.0.1

apple safari 3.0.0

apple safari 2

apple safari 1.2

apple safari 2.0.0

apple safari 3.0.1b

apple safari 3.1.0b

apple safari 3.2.0

apple safari 5.0.4

apple safari

apple safari 1.3.0

apple safari 1.2.3

apple safari 1.0.0b1

apple safari 1.0.0b2

apple safari 3.0.1

apple safari 3.0.0b

apple safari 3

apple safari 3.0.3b

apple safari 4.1.2

apple safari 3.1.1

apple safari 4.1.1

apple safari 3.2.2

apple safari 3.0.2b

apple safari 3.1.2

apple safari 5.0.3

Vendor Advisories

Applications using libxml2 could be made to crash or run programs as your login if they opened a specially crafted file ...
Debian Bug report logs - #652352 Two security issues Package: libxml2; Maintainer for libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Source for libxml2 is src:libxml2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, 16 Dec 2011 14:54:01 UTC ...
Debian Bug report logs - #656377 libxml2: [PATCH] fix for CVE-2011-3919 Package: libxml2; Maintainer for libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Source for libxml2 is src:libxml2 (PTS, buildd, popcon) Reported by: Jamie Strandboge <jamie@ubuntucom> Date: Wed, 18 Jan 2012 21:3 ...
Synopsis Important: libxml2 security update Type/Severity Security Advisory: Important Topic Updated libxml2 packages that fix several security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerabi ...
Synopsis Low: libxml2 security and bug fix update Type/Severity Security Advisory: Low Topic Updated libxml2 packages that fix several security issues and various bugsare now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having lowsecurity impact Commo ...
Synopsis Important: libxml2 security update Type/Severity Security Advisory: Important Topic Updated libxml2 packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerabi ...