CVE-2011-1774
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425.
- Affected products
- Suse Linux Enterprise, Safari, Webkit, Libxslt
- Apple Safari
- ≤ 5.0.5, 1.0, 1.0.0, 1.0.0b1, 1.0.0b2, 1.0.1, 1.0.2, 1.0.3, 1.1, 1.1.0, 1.1.1, 1.2, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.3, 1.3.0, 1.3.1, 1.3.2, 2, 2.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 3, 3.0, 3.0.0, 3.0.0b, 3.0.1, 3.0.1b, 3.0.2, 3.0.2b, 3.0.3, 3.0.3b, 3.0.4
- CVSS 2.0
- 8.8 HIGH
- EPSS
- 43.2% (99th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2011-07-21
CVE-2011-1774 at NVD
11 known exploits for CVE-2011-1774
Proof-of-concept code and exploit modules indexed by Sploitus
Cross Platform Webkit File Dropper
Apple Safari libxslt File Create
Apple Safari libxslt File Create
Apple Safari libxslt File Create
Apple Safari libxslt File Create
Apple Safari Webkit - libxslt Arbitrary File Creation (Metasploit)
Cross Platform Webkit File Dropper
Apple Safari Webkit libxslt Arbitrary File Creation
Apple Safari Webkit libxslt Arbitrary File Creation
Apple Safari Webkit libxslt Arbitrary File Creation
Apple iTunes多个安全漏洞