CVE-2011-1417

Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
Severity
UNKNOWN
AV:N/AC:M/Au:N/C:P/I:P/A:P
Atk. Vector
NETWORK
Atk. Complexity
MEDIUM
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
applemac_os_x
𝑥
≤ 10.6.6
applemac_os_x
10.6.0
applemac_os_x
10.6.1
applemac_os_x
10.6.2
applemac_os_x
10.6.3
applemac_os_x
10.6.4
applemac_os_x
10.6.5
applemac_os_x_server
𝑥
≤ 10.6.6
applemac_os_x_server
10.6.0
applemac_os_x_server
10.6.1
applemac_os_x_server
10.6.2
applemac_os_x_server
10.6.3
applemac_os_x_server
10.6.4
applemac_os_x_server
10.6.5
appleiphone_os
𝑥
≤ 4.2.5
appleiphone_os
1.0.0
appleiphone_os
1.0.1
appleiphone_os
1.0.2
appleiphone_os
1.1.0
appleiphone_os
1.1.1
appleiphone_os
1.1.2
appleiphone_os
1.1.3
appleiphone_os
1.1.4
appleiphone_os
1.1.5
appleiphone_os
2.0
appleiphone_os
2.1
appleiphone_os
2.1.1
appleiphone_os
2.2
appleiphone_os
2.2.1
appleiphone_os
3.0
appleiphone_os
3.0.1
appleiphone_os
3.1
appleiphone_os
3.1.2
appleiphone_os
3.2
appleiphone_os
3.2.1
appleiphone_os
3.2.2
appleiphone_os
4.0
appleiphone_os
4.0.1
appleiphone_os
4.0.2
appleiphone_os
4.1
appleiphone_os
4.2
appleiphone_os
4.2.1
appleiphone_os
4.3.0
appleiphone_os
4.3.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration