Vulnerability index

Browse CVEs

157 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 10.0 CVE-2014-1314 WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox … Mac Os X after 10.9.2 Fix from $1,9502014-04-23 MEDIUM 5.8 CVE-2014-1282 The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requireme… Tvos after 7.0.6 Fix from $1,6002014-03-14 MEDIUM 5.8 CVE-2014-1285 Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveragi… Iphone Os after 7.0.6 Fix from $1,6002014-03-14 MEDIUM 5.0 CVE-2014-1276 IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that acce… Iphone Os after 7.0.6 Fix from $1,6002014-03-14 HIGH 8.8 CVE-2013-5133 Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via c… Iphone Os after 7.0.6 Fix from $1,9502014-03-14 MEDIUM 5.0 CVE-2013-6835EPSS 7% TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remot… Iphone Os after 7.0.6 Fix from $1,6002014-03-14 MEDIUM 6.4 CVE-2013-5227 Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofi… Safari after 6.1 Fix from $1,6002013-12-18 HIGH 7.2 CVE-2013-5148 Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock implementation, which allows … Keynote after 5.3 Fix from $1,9502013-10-24 HIGH 7.5 CVE-2013-5179 App Sandbox in Apple Mac OS X before 10.9 allows attackers to bypass intended sandbox restrictions via a crafted app that uses the LaunchServices int… Mac Os X after 10.8.5 Fix from $1,9502013-10-24 MEDIUM 5.8 CVE-2013-5189 Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-depend… Mac Os X after 10.8.5 Fix from $1,6002013-10-24 MEDIUM 5.0 CVE-2013-5178 LaunchServices in Apple Mac OS X before 10.9 does not properly restrict Unicode characters in filenames, which allows context-dependent attackers to … Mac Os X after 10.8.5 Fix from $1,6002013-10-24 MEDIUM 6.4 CVE-2013-5165 socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers… Mac Os X after 10.8.5 Fix from $1,6002013-10-24 MEDIUM 5.0 CVE-2013-5157 The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post T… Iphone Os after 6.1.4 Fix from $1,6002013-09-19 MEDIUM 6.3 CVE-2013-5145 kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) u… Iphone Os after 6.1.4 Fix from $1,6002013-09-19 MEDIUM 5.8 CVE-2013-0957 Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Era… Iphone Os after 6.1.4 Fix from $1,6002013-09-19 MEDIUM 6.8 CVE-2013-1027 Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which mig… Mac Os X after 10.8.4 Fix from $1,6002013-09-16 MEDIUM 5.5 CVE-2013-1033 Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging… Mac Os X after 10.8.4 Fix from $1,6002013-09-16 HIGH 7.2 CVE-2012-5519 CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0… Cups No fix yet Fix from $1,9502012-11-20 MEDIUM 5.0 CVE-2012-3742 Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which… Iphone Os after 5.1.1 Fix from $1,6002012-09-20 MEDIUM 5.0 CVE-2012-3743 The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sen… Iphone Os after 5.1.1 Fix from $1,6002012-09-20 MEDIUM 6.9 CVE-2012-3728 The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain… Iphone Os after 5.1.1 Fix from $1,6002012-09-20 MEDIUM 5.0 CVE-2012-3698 Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows … Xcode after 4.3.3 Fix from $1,6002012-07-26 HIGH 7.1 CVE-2012-3697 WebKit in Apple Safari before 6.0 does not properly handle file: URLs, which allows remote attackers to bypass intended sandbox restrictions and read… Safari after 5.1.7 Fix from $1,9502012-07-25 MEDIUM 5.0 CVE-2012-0680 Apple Safari before 6.0 does not properly handle the autocomplete attribute of a password input element, which allows remote attackers to bypass auth… Safari after 5.1.7 Fix from $1,6002012-07-25 HIGH 9.3 CVE-2012-0643 The kernel in Apple iOS before 5.1 does not properly handle debug system calls, which allows remote attackers to bypass sandbox restrictions and exec… Iphone Os 5.1+ Fix from $1,9502012-03-08 MEDIUM 5.0 CVE-2012-0585 The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries… Iphone Os 5.1+ Fix from $1,6002012-03-08 MEDIUM 6.8 CVE-2011-3458 QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitra… Mac Os X after 10.7.2 Fix from $1,6002012-02-02 MEDIUM 5.0 CVE-2011-4692 WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for imag… Safari after 15 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2010-5070 The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle… Safari No fix yet Fix from $1,6002011-12-07 HIGH 7.6 CVE-2008-7303 The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attack… Mac Os X No fix yet Fix from $1,9502011-11-15