Vulnerability index

Browse CVEs

390 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Iphone Os HIGH 7.1
CVE-2013-5155

The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite loop) via an application that writes crafted valu…

Fix: after 6.1.4
Fix from $1,950 2013-09-19
Iphone Os HIGH 7.8
CVE-2013-5140

The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion failure and device restart) via an invalid packet fr…

Fix: after 6.1.4
Fix from $1,950 2013-09-19
Mac Os X MEDIUM 6.1
CVE-2011-2391

The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6…

Fix: after 12.1
Fix from $1,600 2013-09-19
Iphone Os MEDIUM 5.8
CVE-2013-1028

The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which …

Fix: after 10.8.4
Fix from $1,600 2013-09-16
Mac Os X MEDIUM 6.9
CVE-2013-3954

The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which a…

Fix: after 6.1.4
Fix from $1,600 2013-06-05
Iphone Os MEDIUM 6.2
CVE-2013-3955

The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an Apple…

No fix yet
Fix from $1,600 2013-06-05
Mac Os X MEDIUM 6.8
CVE-2013-1024

CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote atta…

Fix: after 10.8.3
Fix from $1,600 2013-06-05
Mac Os X MEDIUM 6.8
CVE-2012-3719

Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code vi…

Fix: after 10.7.4
Fix from $1,600 2012-09-20
Ichat Server MEDIUM 5.8
CVE-2012-4672

Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains vi…

Mitigation only
Fix from $1,600 2012-08-25
Safari MEDIUM 5.8
CVE-2012-3689

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origi…

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Safari MEDIUM 5.8
CVE-2012-3691

WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the …

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Safari MEDIUM 5.0
CVE-2012-0676

WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to f…

Fix: after 5.1.6
Fix from $1,600 2012-05-11
Safari MEDIUM 6.4
CVE-2012-0584

The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allo…

Fix: after 5.1.2
Fix from $1,600 2012-03-12
Iphone Os MEDIUM 5.0
CVE-2012-0641

CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensiti…

Fix: 5.1+
Fix from $1,600 2012-03-08
Mac Os X MEDIUM 6.8
CVE-2011-3227

libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation …

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Iphone Os HIGH 7.5
CVE-2011-0228EPSS 6%

The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.50…

Fix: after 4.2.9
Fix from $1,950 2011-08-29
Safari HIGH 8.8
CVE-2011-1774EPSS 43%

WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently…

Fix: after 5.0.5
Fix from $1,950 2011-07-21
Safari HIGH 9.3
CVE-2011-0215

ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code…

Fix: after 5.0.5
Fix from $1,950 2011-07-21
Mac Os X HIGH 7.2
CVE-2011-0182

The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain priv…

Fix: after 10.6.6
Fix from $1,950 2011-03-23
Iphone Os HIGH 7.8
CVE-2011-0162

Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to ca…

Fix: after 4.2
Fix from $1,950 2011-03-11
Iphone Os MEDIUM 5.0
CVE-2011-0159

The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari …

Mitigation only
Fix from $1,600 2011-03-11
Safari MEDIUM 5.0
CVE-2011-0160

WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, wh…

Fix: after 5.0.3
Fix from $1,600 2011-03-11
Mac Os X MEDIUM 6.8
CVE-2010-3788

QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote att…

Patch available
Fix from $1,600 2010-11-16
Mac Os X HIGH 7.1
CVE-2010-1844

Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consum…

Patch available
Fix from $1,950 2010-11-16
Mac Os X MEDIUM 6.8
CVE-2010-1845

ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr…

Patch available
Fix from $1,600 2010-11-16
Mac Os X HIGH 7.8
CVE-2010-1843

Networking in Apple Mac OS X 10.6.2 through 10.6.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) v…

Patch available
Fix from $1,950 2010-11-16
Mac Os X HIGH 9.3
CVE-2010-1841

Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory …

Patch available
Fix from $1,950 2010-11-15
Mac Os X MEDIUM 5.8
CVE-2010-1834

CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to t…

Patch available
Fix from $1,600 2010-11-15
Mac Os X MEDIUM 5.0
CVE-2010-1828

AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemo…

Patch available
Fix from $1,600 2010-11-15
Safari HIGH 9.3
CVE-2010-1807EPSS 61%

WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-poi…

Fix: after 2.1
Fix from $1,950 2010-09-10