CVE-2011-0154
WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory…
Does this matter?
Lower severity and a low EPSS score (2.67%). Track it; it rarely justifies an emergency change on its own.
Description
WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 2.67% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- apple/itunes
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlMailing List, Patch, Vendor Advisory
- http://support.apple.com/kb/HT4554Vendor Advisory
- http://support.apple.com/kb/HT4564Vendor Advisory
- http://support.apple.com/kb/HT4566Broken Link, Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-11-101Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17308Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlMailing List, Patch, Vendor Advisory
- http://support.apple.com/kb/HT4554Vendor Advisory
- http://support.apple.com/kb/HT4564Vendor Advisory
- http://support.apple.com/kb/HT4566Broken Link, Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-11-101Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17308Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.