The Month of Apple Bugs (MOAB) started off smoothly with the release of three bugs so far on day 3. They are all related to media player.

- Apple QuickTime
rtsp://URL Handler Stack-based Buffer Overflow - A vulnerability in the handling of thertsp://URL handler allows remote arbitrary code execution. - VLC Media Player
udp://Format String Vulnerability - A vulnerability in the handling of theudp://URL handler allows remote arbitrary code execution. - Apple QuickTime HREFTrack Cross-Zone Scripting vulnerability - A vulnerability in the handling of the HREFTrack field allows to perform cross-zone scripting, leading to potential remote arbitrary code execution.
What is interesting is not OS X has enough bugs for a whole month but the voluntary efforts by Mac guru, Landon Fuller. He has provided patches or fixes for all three bugs disclosed so far. He also offers to patch all other vulnerabilities, one a day, until the month is out.