MacNN | vulnerability News http://www.macnn.com/ MacNN is the leading source for news about Apple and the Mac industry. It offers news, reviews, discussion, tips, troubleshooting, links, and reviews every day. The best place for Mac News. Period. en-us vulnerability, Latest News, Headlines, Stories; http://images.macnn.com/images/macnn-logo-bw.gif http://www.macnn.com/ Firefox 3.5 JS security vulnerability emerges http://www.macnn.com/articles/09/07/15/firefox.security.issue/ <img align='left' src='http://images.macnn.com/esta/content/0906/firefox35.jpg' border='0' width='176' height='120' />A new security vulnerability affecting Firefox 3.5 has been discovered, according to Secunia. The issue, spotted by Simon Berry-Byrne, relates to an error when processing JavaScript code, such as "font" HTML tags, and can be exploited to cause memory corruption. The flaw potentially could be used to allow malicious code to enable unauthorized control of a system.... http://www.macnn.com/articles/09/07/15/firefox.security.issue/ Wed, 15 Jul 2009 04:40:00 GMT iCal vulnerable to malicious .ics files http://www.macnn.com/articles/08/05/21/ical.vulnerable.to.bad.ics/ <img align='left' src='http://images.macnn.com/macnn/news/0805/21-ical-sm.jpg' border='0' width='176' height='120' />A new vulnerability in iCal has been discovered that allows un-authenticated attackers to execute arbitrary code on vulnerable systems with (and potentially without) the assistance from the end user of the application or to repeateadly execute a denial of service attack to crash the iCal application. Core Security writes that "the most serious of the three vulnerabilities is due to potential memor... http://www.macnn.com/articles/08/05/21/ical.vulnerable.to.bad.ics/ Wed, 21 May 2008 20:05:00 GMT URL spoofing flaw affects Safari 3.1.1 http://www.macnn.com/articles/08/04/24/url.spoofing.flaw/ <img align='left' src='http://images.macnn.com/macnn/news/0802/28-safari-sm.jpg' border='0' width='176' height='120' />A little over a week after Apple offered a security update to Safari 3.1.1, security research site Secunia warned users about another, but "less critical," vulnerability that could allows malicious sites to "spoof" other websites. Reported by Juan Pablo Lopez Yacubian, the security advisory notes that Safari 3.11 has a flaw that can be exploited by malicious people to display a fake URL in the add... http://www.macnn.com/articles/08/04/24/url.spoofing.flaw/ Fri, 25 Apr 2008 01:00:00 GMT Code crashes Safari in iPhone 1.1.4, fixed for Mac/PC http://www.macnn.com/articles/08/03/19/code.crashes.iphone.114/ <img align='left' src='http://images.macnn.com/macnn/news/0803/18-vulnerability-sm.jpg' border='0' width='176' height='120' />A new exploit has surfaced for the iPhone's Safari browser that, while drawing parallels to an earlier issue, requires no user input to function. According to iPhone World, the vulnerability is triggered by previously conceived code that has been refined in the above manner. The issue affects firmware version 1.1.4 iPhones, and presumably previous versions. Safari on the Mac and PC were also affec... http://www.macnn.com/articles/08/03/19/code.crashes.iphone.114/ Wed, 19 Mar 2008 04:30:00 GMT DoS attack on iPhone causes memory leak, freeze http://www.macnn.com/articles/08/01/26/new.iphone.vulnerability/ <img align='left' src='http://images.macnn.com/macnn/news/0801/26-dos-sm.jpg' border='0' width='176' height='120' />iPhone owners should be on guard against a new threat, which fortunately doesn't harm the device, but still induces a freeze by taking all available system memory. According to security firm SecurityFocus, the vulnerability is exposed by a Denial of Service attack, when a maliciously crafted webpage is viewed. The page will insert code into the iPhone, which continually eats up available system me... http://www.macnn.com/articles/08/01/26/new.iphone.vulnerability/ Sat, 26 Jan 2008 18:25:00 GMT iPhone Trojan revealed, targets jailbroken phones http://www.macnn.com/articles/08/01/09/first.iphone.trojan.attack/ <img align='left' src='http://images.macnn.com/macnn/news/0711/19-iphone-sm.jpg' border='0' width='176' height='120' />The iPhone recently fell victim to its first Trojan attack, which came in the form of a malicious file named ì113 prepî. While installation of the phony application is relatively benign ñ the app merely says ìshoesî when activated ñ uninstalling the file causes damage to or deletes system-critical files in the /bin directory on the iPhone. In addition to harming the devices own software, third par... http://www.macnn.com/articles/08/01/09/first.iphone.trojan.attack/ Wed, 09 Jan 2008 05:10:00 GMT Firebox X protects against Java vulnerabilities http://www.macnn.com/articles/07/12/17/firebox.x.updated/ <img align='left' src='http://images.macnn.com/macnn/news/0712/17-firebox-sm.jpg' border='0' width='176' height='120' />WatchGuard Technologies recently updated its Firebox X network protection hardware to neutralize the latest Java threats against Mac OS X 10.4 Tiger users. Malicious web pages are reportedly the most common methods of implementation for viruses or attacks, but WatchGuard says that its equipment prevents against these kind of incursions by running network traffic through its Application Proxy techn... http://www.macnn.com/articles/07/12/17/firebox.x.updated/ Tue, 18 Dec 2007 04:20:00 GMT iPhone will be hacker's choice in 2008 - report http://www.macnn.com/articles/07/12/11/iphone.target.of.choice/ <img align='left' src='http://images.macnn.com/macnn/news/0712/app_071206_iphonesm.jpg' border='0' width='176' height='120' />The iPhone will be a major target for hackers in 2008, with attacks centered around the included Safari web browser, according to a prediction by Arbor Networks Security. The attacks will most likely be bits of malicious code that, when intertwined with benign digital material such as image files, could be capable of executing various harmful commands on the device. Arbor believes that the prospec... http://www.macnn.com/articles/07/12/11/iphone.target.of.choice/ Tue, 11 Dec 2007 22:25:00 GMT First Look: Symantec's Norton AntiVirus 11 http://www.macnn.com/articles/07/12/11/first.look.at.nav.11/ <img align='left' src='http://images.macnn.com/macnn/news/0712/11-nav-sm.jpg' border='0' width='176' height='120' />Viruses have been of little concern to most Mac users since OS X made its first appearance in 2001. Apple's switch to Intel processors, and the various virtualization processes that exist for running Windows, have eroded that confidence for some users. Although Apple is usually on the ball with fixing system vulnerabilities, some larger problems can go for several days or weeks before a proper fix... http://www.macnn.com/articles/07/12/11/first.look.at.nav.11/ Tue, 11 Dec 2007 20:25:00 GMT Security flaws surface in Leopard, VPN http://www.macnn.com/articles/07/12/10/security.flaws.in.leopard/ <img align='left' src='http://images.macnn.com/macnn/news/0712/hei_071210_heisesm.jpg' border='0' width='176' height='120' />A new denial of service (DoS) vulnerability has surfaced in Apple's Mac OS X Leopard operating system that can result in crashes, according to Heise Security. The flaw, which is an integer overflow in the load_threadstack function in mach_loader.c, occurs when processing Mach-O binaries and can lead to a kernel panic. Single user systems should not be at risk, according to the company, but multi-u... http://www.macnn.com/articles/07/12/10/security.flaws.in.leopard/ Mon, 10 Dec 2007 22:25:00 GMT