Vulnerability index

Browse CVEs

390 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Mac Os X HIGH 7.8
CVE-2016-1733

AppleRAID in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrup…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Iphone Os CRITICAL 9.8
CVE-2016-0801EPSS 33%

The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to ex…

Fix: after 10.11.3
Fix from $2,300 2016-02-07
Tvos HIGH 9.3
CVE-2015-7079

dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged cont…

Fix: after 9.1
Fix from $1,950 2015-12-11
Iphone Os HIGH 9.3
CVE-2015-7072

dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code…

Fix: after 9.1
Fix from $1,950 2015-12-11
Watchos HIGH 7.2
CVE-2015-7047

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted …

Fix: after 10.11.1
Fix from $1,950 2015-12-11
Mac Os X HIGH 7.5
CVE-2015-7036EPSS 39%

The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or …

Fix: after 10.10.3
Fix from $1,950 2015-11-22
Mac Os X HIGH 7.2
CVE-2015-5945

The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters.

Fix: after 10.11.0
Fix from $1,950 2015-10-23
Iphone Os HIGH 7.1
CVE-2015-7004

The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

Fix: after 9.0.2
Fix from $1,950 2015-10-23
Mac Os X MEDIUM 5.0
CVE-2015-5883

The bidirectional text-display and text-selection implementations in Terminal in Apple OS X before 10.11 interpret directional override formatting ch…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Safari HIGH 10.0
CVE-2015-5780

The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has u…

Fix: after 8.0.8
Fix from $1,950 2015-10-09
Iphone Os MEDIUM 5.0
CVE-2015-5879

XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-n…

Fix: after 10.10.5
Fix from $1,600 2015-09-18
Iphone Os HIGH 7.2
CVE-2015-3805

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Iphone Os HIGH 7.2
CVE-2015-3803

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted multi-architecture execu…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Iphone Os HIGH 7.2
CVE-2015-3802

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Mac Os X HIGH 7.2
CVE-2015-3760

dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unspecifie…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Mac Os X MEDIUM 6.8
CVE-2015-1139

ImageIO in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted…

Fix: 10.10.3+
Fix from $1,600 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1135

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1134

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1133

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 10.0
CVE-2015-1132

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1131

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1104EPSS 7%

The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2015-1105EPSS 9%

The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly implement the Urge…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Iphone Os HIGH 7.5
CVE-2015-1103

The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing changes in response to ICMP_REDIRECT messages, w…

Fix: after 10.10.2
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.1
CVE-2015-1102

The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly handle TCP headers, which allows man-in-the-…

Fix: after 10.10.2
Fix from $1,950 2015-04-10
Iphone Os MEDIUM 6.8
CVE-2015-1088

CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code …

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Tvos MEDIUM 6.9
CVE-2015-1086

The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly validate IOKit object metadata, which allows attackers …

Fix: after 8.2
Fix from $1,600 2015-04-10
Mac Os X HIGH 10.0
CVE-2014-8836

The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (ar…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 7.2
CVE-2014-8825

The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows loc…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 10.0
CVE-2014-8824

The kernel in Apple OS X before 10.10.2 does not properly validate IODataQueue object metadata fields, which allows attackers to execute arbitrary co…

Fix: after 10.10.1
Fix from $1,950 2015-01-30