Vulnerability index

Browse CVEs

358 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mac Os X MEDIUM 5.0
CVE-2014-1361

Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only …

Fix: after 7.1.1
Fix from $1,600 2014-07-01
Safari MEDIUM 5.0
CVE-2013-5130

WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes it easier for context-depende…

Fix: after 6.0.5
Fix from $1,600 2013-10-24
Iphone Os MEDIUM 5.0
CVE-2012-3749

The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which mak…

Fix: after 6.0
Fix from $1,600 2012-11-03
Iphone Os MEDIUM 5.0
CVE-2012-3724

CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information b…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Mac Os X MEDIUM 5.0
CVE-2012-0651

The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a …

Mitigation only
Fix from $1,600 2012-05-11
Safari MEDIUM 5.0
CVE-2012-0640

WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remot…

Fix: after 5.1.3
Fix from $1,600 2012-03-12
Safari MEDIUM 5.0
CVE-2012-0647

WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers …

Fix: after 5.1.3
Fix from $1,600 2012-03-12
Safari MEDIUM 5.0
CVE-2011-3242

The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of the Block Cookies setting, whic…

Fix: after 5.1
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 5.0
CVE-2011-3246

CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to …

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 5.0
CVE-2011-0231

CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to…

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Iphone Os MEDIUM 5.0
CVE-2011-1418

The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4…

Fix: after 4.2
Fix from $1,600 2011-03-11
Cfnetwork MEDIUM 5.0
CVE-2010-1800

CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a conn…

Patch available
Fix from $1,600 2010-08-25
Mac Os X Server MEDIUM 5.0
CVE-2010-0523

Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2010-03-30
Webkit MEDIUM 5.8
CVE-2010-1126

The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intende…

Mitigation only
Fix from $1,600 2010-03-26
Safari HIGH 7.1
CVE-2009-2200

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-ass…

Fix: after 4.0.2
Fix from $1,950 2009-08-12
Safari HIGH 7.1
CVE-2009-1703

WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 7.1
CVE-2009-1713

The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read …

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 7.1
CVE-2009-1718

WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dra…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari MEDIUM 5.0
CVE-2009-1706

The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstanc…

Fix: after 3.2.3
Fix from $1,600 2009-06-10
Safari HIGH 7.1
CVE-2009-0123

Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vector…

No fix yet
Fix from $1,950 2009-01-15
Mail MEDIUM 5.0
CVE-2008-4491

Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email s…

Mitigation only
Fix from $1,600 2008-10-08
Safari MEDIUM 5.0
CVE-2008-3171

Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive …

Mitigation only
Fix from $1,600 2008-07-14
Xcode MEDIUM 5.0
CVE-2008-2318

The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remo…

Fix: after 3.0
Fix from $1,600 2008-07-14
Mac Os X MEDIUM 5.0
CVE-2008-1579

Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message pr…

Patch available
Fix from $1,600 2008-06-02
Mac Os X MEDIUM 6.8
CVE-2008-0052

CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.0
CVE-2008-0050

CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.0
CVE-2008-0041

Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determ…

Patch available
Fix from $1,600 2008-02-12
Mac Os X MEDIUM 5.0
CVE-2007-4688

The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addr…

Patch available
Fix from $1,600 2007-11-15