libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Libsecurity | — | Upgrade macOS to the latest versionApply OS X security update 2012-002 | Jul 16, 2012 | May 10, 2012 |
| Apple Osx Loginwindow | — | Apply OS X security update 2012-002Upgrade macOS to the latest version | Aug 28, 2015 | May 10, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub