Vulnerability index

Browse CVEs

157 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Mac Os X HIGH 10.0
CVE-2014-1314

WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox …

Fix: after 10.9.2
Fix from $1,950 2014-04-23
Tvos MEDIUM 5.8
CVE-2014-1282

The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requireme…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.8
CVE-2014-1285

Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveragi…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.0
CVE-2014-1276

IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that acce…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os HIGH 8.8
CVE-2013-5133

Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via c…

Fix: after 7.0.6
Fix from $1,950 2014-03-14
Iphone Os MEDIUM 5.0
CVE-2013-6835EPSS 7%

TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remot…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Safari MEDIUM 6.4
CVE-2013-5227

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofi…

Fix: after 6.1
Fix from $1,600 2013-12-18
Keynote HIGH 7.2
CVE-2013-5148

Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock implementation, which allows …

Fix: after 5.3
Fix from $1,950 2013-10-24
Mac Os X HIGH 7.5
CVE-2013-5179

App Sandbox in Apple Mac OS X before 10.9 allows attackers to bypass intended sandbox restrictions via a crafted app that uses the LaunchServices int…

Fix: after 10.8.5
Fix from $1,950 2013-10-24
Mac Os X MEDIUM 5.8
CVE-2013-5189

Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-depend…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Mac Os X MEDIUM 5.0
CVE-2013-5178

LaunchServices in Apple Mac OS X before 10.9 does not properly restrict Unicode characters in filenames, which allows context-dependent attackers to …

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Mac Os X MEDIUM 6.4
CVE-2013-5165

socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Iphone Os MEDIUM 5.0
CVE-2013-5157

The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post T…

Fix: after 6.1.4
Fix from $1,600 2013-09-19
Iphone Os MEDIUM 6.3
CVE-2013-5145

kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) u…

Fix: after 6.1.4
Fix from $1,600 2013-09-19
Iphone Os MEDIUM 5.8
CVE-2013-0957

Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Era…

Fix: after 6.1.4
Fix from $1,600 2013-09-19
Mac Os X MEDIUM 6.8
CVE-2013-1027

Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which mig…

Fix: after 10.8.4
Fix from $1,600 2013-09-16
Mac Os X MEDIUM 5.5
CVE-2013-1033

Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging…

Fix: after 10.8.4
Fix from $1,600 2013-09-16
Cups HIGH 7.2
CVE-2012-5519

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0…

No fix yet
Fix from $1,950 2012-11-20
Iphone Os MEDIUM 5.0
CVE-2012-3742

Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Iphone Os MEDIUM 5.0
CVE-2012-3743

The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sen…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Iphone Os MEDIUM 6.9
CVE-2012-3728

The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Xcode MEDIUM 5.0
CVE-2012-3698

Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows …

Fix: after 4.3.3
Fix from $1,600 2012-07-26
Safari HIGH 7.1
CVE-2012-3697

WebKit in Apple Safari before 6.0 does not properly handle file: URLs, which allows remote attackers to bypass intended sandbox restrictions and read…

Fix: after 5.1.7
Fix from $1,950 2012-07-25
Safari MEDIUM 5.0
CVE-2012-0680

Apple Safari before 6.0 does not properly handle the autocomplete attribute of a password input element, which allows remote attackers to bypass auth…

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Iphone Os HIGH 9.3
CVE-2012-0643

The kernel in Apple iOS before 5.1 does not properly handle debug system calls, which allows remote attackers to bypass sandbox restrictions and exec…

Fix: 5.1+
Fix from $1,950 2012-03-08
Iphone Os MEDIUM 5.0
CVE-2012-0585

The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries…

Fix: 5.1+
Fix from $1,600 2012-03-08
Mac Os X MEDIUM 6.8
CVE-2011-3458

QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitra…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Safari MEDIUM 5.0
CVE-2011-4692

WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for imag…

Fix: after 15
Fix from $1,600 2011-12-07
Safari MEDIUM 5.0
CVE-2010-5070

The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle…

No fix yet
Fix from $1,600 2011-12-07
Mac Os X HIGH 7.6
CVE-2008-7303

The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attack…

No fix yet
Fix from $1,950 2011-11-15