CVE-2011-0133
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for fl
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with pseudo-elements, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
HIGH · CVSS 7.6
EPSS 0.00863
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0