CVE-2011-0190
Last modified
CVE-2011-0190 is a vulnerability of currently unknown severity. Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Installer | All versions |
| Apple | Mac Os X | 10.6.0 |
| Apple | Mac Os X | 10.6.1 |
| Apple | Mac Os X | 10.6.2 |
| Apple | Mac Os X | 10.6.3 |
| Apple | Mac Os X | 10.6.4 |
| Apple | Mac Os X | 10.6.5 |
| Apple | Mac Os X | 10.6.6 |
| Apple | Mac Os X Server | 10.6.0 |
| Apple | Mac Os X Server | 10.6.1 |
| Apple | Mac Os X Server | 10.6.2 |
| Apple | Mac Os X Server | 10.6.3 |
| Apple | Mac Os X Server | 10.6.4 |
| Apple | Mac Os X Server | 10.6.5 |
| Apple | Mac Os X Server | 10.6.6 |
References
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT4581Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT4581Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0190?
How severe is CVE-2011-0190?
How do I fix CVE-2011-0190?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-0184QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote…
- CVE-2011-0185Format string vulnerability in the debug-logging feature in …
- CVE-2011-0186QuickTime in Apple Mac OS X before 10.6.7 allows remote atta…
- CVE-2011-0187The plug-in in QuickTime in Apple Mac OS X before 10.6.7 all…
- CVE-2011-0188The VpMemAlloc function in bigdecimal.c in the BigDecimal cl…
- CVE-2011-0189The default configuration of Terminal in Apple Mac OS X 10.6…
- CVE-2011-0191Buffer overflow in LibTIFF 3.9.4 and possibly other versions…
- CVE-2011-0192Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly …
- CVE-2011-0193Multiple buffer overflows in Image RAW in Apple Mac OS X bef…
- CVE-2011-0194Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10…
- CVE-2011-0195The generate-id XPath function in libxslt in Apple iOS 4.3.x…
- CVE-2011-0196AirPort in Apple Mac OS X 10.5.8 allows remote attackers to …
Are you affected by CVE-2011-0190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
