Summary
This host is missing an important security update according to Java for Mac OS X 10.6 Update 6 and 10.7 Update 1.
Impact
Successful exploitation may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user.
Impact Level: System/Application
Solution
Upgrade to Java for Mac OS X 10.6 Update 6 and 10.7 Update 1, For updates refer to http://support.apple.com/kb/HT5045
Insight
For more information on the vulnerabilities refer the below links.
Affected
Java for Mac OS X v10.6.6 and v10.7.2 or Mac OS X Server v10.6.8 and v10.7.2.
References
Severity
Classification
-
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Mac OS X v10.6.7 Multiple Vulnerabilities (2011-002)
- Microsoft Office Word Remote Code Execution Vulnerabilities-3017301 (Mac OS X)
- Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
- Microsoft Office Remote Code Execution Vulnerabilities-2858300 (Mac OS X)
- Mac OS X 10.5.6 Update / Mac OS X Security Update 2008-008