CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
78.0%
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.
Vendor | Product | Version | CPE |
---|---|---|---|
apple | safari | * | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
apple | safari | 4.0 | cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:* |
apple | safari | 4.0.0b | cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:* |
apple | safari | 4.0.1 | cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:* |
apple | safari | 4.0.2 | cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:* |
apple | safari | 4.0.3 | cpe:2.3:a:apple:safari:4.0.3:*:*:*:*:*:*:* |
microsoft | windows | * | cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
lists.apple.com/archives/security-announce/2010//Mar/msg00003.html
lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
lists.apple.com/archives/security-announce/2010/Jun/msg00003.html
lists.apple.com/archives/security-announce/2010/Mar/msg00000.html
secunia.com/advisories/39135
secunia.com/advisories/42314
support.apple.com/kb/HT4070
support.apple.com/kb/HT4077
support.apple.com/kb/HT4105
support.apple.com/kb/HT4225
support.apple.com/kb/HT4456
www.securityfocus.com/bid/38671
www.securityfocus.com/bid/38677
www.securitytracker.com/id?1023706
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7561