Vulnerability index

Browse CVEs

390 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Iphone Os MEDIUM 6.8
CVE-2014-4494

Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, …

Fix: after 8.1.2
Fix from $1,600 2015-01-30
Safari MEDIUM 5.0
CVE-2014-4465

WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Casc…

Fix: after 8.1.2
Fix from $1,600 2014-12-10
Iphone Os HIGH 9.3
CVE-2014-4461

The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers t…

Fix: after 10.10.1
Fix from $1,950 2014-11-18
Mac Os X HIGH 7.8
CVE-2014-4443

Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.1 data.

Fix: after 10.9.5
Fix from $1,950 2014-10-18
Mac Os X MEDIUM 5.0
CVE-2014-4417

Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outage) via a web site that trigg…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X HIGH 9.3
CVE-2014-7861

The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2014-10-05
Mac Os X MEDIUM 6.9
CVE-2014-4416

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X HIGH 9.3
CVE-2014-4390

Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context …

Mitigation only
Fix from $1,950 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4394

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4395

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4396

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4397

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4398

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4399

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4400

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4401

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Iphone Os HIGH 7.8
CVE-2014-4418

IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary…

Fix: after 7.1.2
Fix from $1,950 2014-09-18
Mac Os X HIGH 7.8
CVE-2014-4388

IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary…

Fix: after 10.9.5
Fix from $1,950 2014-09-18
Safari MEDIUM 5.0
CVE-2014-1346

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spo…

Fix: after 6.1.3
Fix from $1,600 2014-05-22
Mac Os X HIGH 10.0
CVE-2014-1318

The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code…

Fix: after 10.9.2
Fix from $1,950 2014-04-23
Mac Os X MEDIUM 5.0
CVE-2014-1316

Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon exit) via ASN.1 data encountere…

Fix: after 10.9.2
Fix from $1,600 2014-04-23
Safari MEDIUM 5.0
CVE-2014-1297

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers …

Fix: after 6.1.2
Fix from $1,600 2014-04-02
Iphone Os HIGH 7.8
CVE-2014-1271

CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of s…

Fix: after 7.0.6
Fix from $1,950 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1267

The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile confi…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1273

dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing requirements by leveraging use of text-relocation instru…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Mac Os X MEDIUM 6.6
CVE-2014-0106

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local…

Fix: after 10.10.4
Fix from $1,600 2014-03-11
Mac Os X MEDIUM 6.4
CVE-2014-2234

A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL ha…

Fix: after 10.9.2
Fix from $1,600 2014-03-05
Mac Os X HIGH 7.5
CVE-2014-1255

Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free function, which allows attackers to bypass the App…

Fix: after 10.9.1
Fix from $1,950 2014-02-27
Mac Os X MEDIUM 6.8
CVE-2013-5168

Console in Apple Mac OS X before 10.9 allows user-assisted remote attackers to execute arbitrary applications by triggering a log entry with a crafte…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Mac Os X MEDIUM 6.6
CVE-2013-5175

The kernel in Apple Mac OS X before 10.9 allows local users to obtain sensitive information or cause a denial of service (out-of-bounds read and syst…

Fix: after 10.8.5
Fix from $1,600 2013-10-24