Integer overflow in QuickLook, as used in Apple Mac OS X prior to 10.6.7 and MobileSafari in Apple iOS prior to 4.2.7 and 4.3.x prior to 4.3.2, allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple mac os x 10.6.3 |
||
apple mac os x 10.6.4 |
||
apple mac os x 10.6.5 |
||
apple mac os x |
||
apple mac os x server 10.6.4 |
||
apple mac os x server 10.6.5 |
||
apple mac os x server |
||
apple mac os x 10.6.1 |
||
apple mac os x server 10.6.1 |
||
apple mac os x server 10.6.3 |
||
apple mac os x 10.6.0 |
||
apple mac os x 10.6.2 |
||
apple mac os x server 10.6.0 |
||
apple mac os x server 10.6.2 |
||
apple iphone os 4.0.1 |
||
apple iphone os 4.0 |
||
apple iphone os 3.2.2 |
||
apple iphone os 3.2.1 |
||
apple iphone os 1.1.3 |
||
apple iphone os 1.1.2 |
||
apple iphone os 1.1.1 |
||
apple iphone os 1.1.0 |
||
apple iphone os 1.0.2 |
||
apple iphone os |
||
apple iphone os 3.0 |
||
apple iphone os 2.2.1 |
||
apple iphone os 2.2 |
||
apple iphone os 2.1.1 |
||
apple iphone os 4.2 |
||
apple iphone os 4.0.2 |
||
apple iphone os 3.2 |
||
apple iphone os 3.1 |
||
apple iphone os 2.0 |
||
apple iphone os 1.1.4 |
||
apple iphone os 1.0.0 |
||
apple iphone os 4.3.1 |
||
apple iphone os 4.2.1 |
||
apple iphone os 4.1 |
||
apple iphone os 3.1.2 |
||
apple iphone os 3.0.1 |
||
apple iphone os 2.1 |
||
apple iphone os 1.1.5 |
||
apple iphone os 1.0.1 |
||
apple iphone os 4.3.0 |