CVE-2011-0216

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.

References

http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html

http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html

http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html

http://rhn.redhat.com/errata/RHSA-2013-0217.html

http://support.apple.com/kb/HT4808

http://support.apple.com/kb/HT4999

http://support.apple.com/kb/HT5001

http://www.debian.org/security/2012/dsa-2394

http://www.mandriva.com/security/advisories?name=MDVSA-2011:188

http://www.redhat.com/support/errata/RHSA-2011-1749.html

Details

Source: MITRE

Published: 2011-07-21

Updated: 2013-02-07

Type: CWE-189

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Vulnerable Software

Configuration 1

AND

OR

cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0:beta:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0:beta2:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.0b1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.0b2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.3:85.8:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.3:85.8.1:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.1.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.1.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.4:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.5:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.2:312.5:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.2:312.6:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.8:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.9:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.9.2:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.9.3:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.0b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.1b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.2b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.3b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.4b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.0b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.1.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.1.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:5.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:5.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:5.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:5.0.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:5.0.4:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*

OR

cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*

Tenable Plugins

View all (32 total)

IDNameProductFamilySeverity
89109VMware ESX Service Console Multiple Vulnerabilities (VMSA-2012-0008) (remote check)NessusMisc.
critical
89037VMware ESX / ESXi libxml2 Multiple Vulnerabilities (VMSA-2012-0012) (remote check)NessusMisc.
high
80688Oracle Solaris Third-Party Patch Update : libxml2 (cve_2011_0216_denial_of)NessusSolaris Local Security Checks
high
79283RHEL 5 : rhev-hypervisor5 (RHSA-2012:0168)NessusRed Hat Local Security Checks
high
70884ESXi 5.0 < Build 764879 Multiple Vulnerabilities (remote check)NessusMisc.
high
68721Oracle Linux 6 : mingw32-libxml2 (ELSA-2013-0217)NessusOracle Linux Local Security Checks
high
68429Oracle Linux 5 : libxml2 (ELSA-2012-0017)NessusOracle Linux Local Security Checks
high
68428Oracle Linux 4 : libxml2 (ELSA-2012-0016)NessusOracle Linux Local Security Checks
high
64425Scientific Linux Security Update : mingw32-libxml2 on SL6.x (x86_64) (20130131)NessusScientific Linux Local Security Checks
high
64391RHEL 6 : mingw32-libxml2 (RHSA-2013:0217)NessusRed Hat Local Security Checks
high
64384CentOS 6 : mingw32-libxml2 (CESA-2013:0217)NessusCentOS Local Security Checks
high
62324Fedora 16 : libxml2-2.7.8-8.fc16 (2012-13824)NessusFedora Local Security Checks
high
62323Fedora 17 : libxml2-2.7.8-9.fc17 (2012-13820)NessusFedora Local Security Checks
high
61217Scientific Linux Security Update : libxml2 on SL5.x i386/x86_64 (20120111)NessusScientific Linux Local Security Checks
high
61216Scientific Linux Security Update : libxml2 on SL4.x i386/x86_64 (20120111)NessusScientific Linux Local Security Checks
high
61192Scientific Linux Security Update : libxml2 on SL6.x i386/x86_64NessusScientific Linux Local Security Checks
critical
59966VMSA-2012-0012 : VMware ESXi update to third-party libraryNessusVMware ESX Local Security Checks
high
60026Apple iOS < 5.0 Multiple Vulnerabilities (BEAST)NessusMobile Devices
critical
58903VMSA-2012-0008 : VMware ESX updates to ESX Service ConsoleNessusVMware ESX Local Security Checks
high
57702Debian DSA-2394-1 : libxml2 - several vulnerabilitiesNessusDebian Local Security Checks
high
57615Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 / 11.10 : libxml2 vulnerabilities (USN-1334-1)NessusUbuntu Local Security Checks
high
57492RHEL 5 : libxml2 (RHSA-2012:0017)NessusRed Hat Local Security Checks
high
57491RHEL 4 : libxml2 (RHSA-2012:0016)NessusRed Hat Local Security Checks
high
57487CentOS 5 : libxml2 (CESA-2012:0017)NessusCentOS Local Security Checks
high
57486CentOS 4 : libxml2 (CESA-2012:0016)NessusCentOS Local Security Checks
high
57320Mandriva Linux Security Advisory : libxml2 (MDVSA-2011:188)NessusMandriva Local Security Checks
high
57022RHEL 6 : libxml2 (RHSA-2011:1749)NessusRed Hat Local Security Checks
critical
6041Apple iOS < 5.0 Multiple Vulnerabilities Nessus Network MonitorMobile Devices
high
55639Safari < 5.1 Multiple VulnerabilitiesNessusWindows
high
55638Mac OS X : Apple Safari < 5.1 / 5.0.6NessusMacOS X Local Security Checks
critical
800988Safari < 5.1 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
5992Safari < 5.1 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high