Vulnerability index

Browse CVEs

358 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Safari MEDIUM 6.5
CVE-2016-1785

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, w…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1779

WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Iphone Os MEDIUM 5.4
CVE-2016-1730

WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.

Fix: after 9.2
Fix from $1,600 2016-02-01
Xcode MEDIUM 5.0
CVE-2015-7056

IDE SCM in Apple Xcode before 7.2 does not recognize .gitignore files, which allows remote attackers to obtain sensitive information in opportunistic…

Fix: after 7.1.1
Fix from $1,600 2015-12-11
Mac Os X MEDIUM 5.0
CVE-2015-7761

Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecifi…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Xcode MEDIUM 5.0
CVE-2015-5909

IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain pote…

Fix: after 6.4
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5906

The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5885

The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.

Fix: after 10.10.5
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5860

The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5858

The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain s…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Mac Os X MEDIUM 5.0
CVE-2015-5831

NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sen…

Fix: after 10.10.5
Fix from $1,600 2015-09-18
Safari MEDIUM 5.0
CVE-2015-5827

WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) cust…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Mac Os X MEDIUM 5.0
CVE-2015-3784

Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an ext…

Fix: after 10.10.4
Fix from $1,600 2015-08-16
Mac Os X MEDIUM 5.0
CVE-2015-3762

The Text Formats component in Apple OS X before 10.10.5, as used in TextEdit, allows remote attackers to read arbitrary files via a text file contain…

Fix: after 10.10.4
Fix from $1,600 2015-08-16
Safari MEDIUM 5.0
CVE-2015-3753

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perfor…

Fix: 6.2.8 / 7.1.8+
Fix from $1,600 2015-08-16
Safari MEDIUM 5.0
CVE-2015-3752

The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.…

Fix: 6.2.8 / 7.1.8+
Fix from $1,600 2015-08-16
Mac Os X MEDIUM 5.0
CVE-2015-1148

Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sens…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2015-1147

Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates…

Fix: 10.10.3+
Fix from $1,600 2015-04-10
Safari MEDIUM 5.0
CVE-2015-1128

The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsin…

Fix: after 6.2.4
Fix from $1,600 2015-04-10
Safari MEDIUM 5.0
CVE-2015-1112

Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-h…

Fix: after 8.2
Fix from $1,600 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1111

Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain s…

Fix: after 8.2
Fix from $1,600 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1110

The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-downlo…

Fix: after 8.2
Fix from $1,600 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1090

CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing ac…

Fix: after 8.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2015-1089

CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, wh…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2014-8839

Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to di…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Iphone Os MEDIUM 5.0
CVE-2014-4491

The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addre…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X MEDIUM 5.0
CVE-2014-4458

The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might all…

Fix: after 10.10.0
Fix from $1,600 2014-11-18
Iphone Os MEDIUM 5.0
CVE-2014-4453

Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight o…

Fix: after 10.10.0
Fix from $1,600 2014-11-18
Iphone Os MEDIUM 5.0
CVE-2014-4361

The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, which allows attackers to deter…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.0
CVE-2014-4362

The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to o…

Fix: after 7.1.2
Fix from $1,600 2014-09-18