Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Mac Os X MEDIUM 6.8
CVE-2016-7585

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Safari MEDIUM 6.8
CVE-2016-4763

WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HT…

Fix: after 12.4.3
Fix from $1,600 2016-09-25
Os X Server HIGH 7.5
CVE-2016-4754

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mech…

Fix: after 5.1
Fix from $1,950 2016-09-25
Iphone Os MEDIUM 5.9
CVE-2016-1788

Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which…

Fix: after 10.11.3
Fix from $1,600 2016-03-24
Mac Os X Server HIGH 7.5
CVE-2016-1777

Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection …

Fix: after 5.0.15
Fix from $1,950 2016-03-24
Software Update MEDIUM 5.9
CVE-2016-1731

Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying t…

Fix: after 2.1.3.127
Fix from $1,600 2016-03-14
Iphone Os MEDIUM 6.8
CVE-2014-8840

The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirectio…

Fix: after 8.1.2
Fix from $1,600 2015-01-30
Iphone Os MEDIUM 6.8
CVE-2014-4449

iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser…

Fix: after 8.0.2
Fix from $1,600 2014-10-22
Mac Os X MEDIUM 5.4
CVE-2014-4428

Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by lever…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4391

The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bundles, which allows remote att…

Fix: after 10.9.4
Fix from $1,600 2014-10-18
Tvos HIGH 8.1
CVE-2014-4422

The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator during the early portion of the boot process, which…

Fix: after 7.1.2
Fix from $1,950 2014-09-18
Iphone Os MEDIUM 5.6
CVE-2014-4364

The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to cal…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Itunes MEDIUM 5.8
CVE-2014-1242

Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control ov…

Fix: after 11.1.3
Fix from $1,600 2014-01-23
Mac Os X MEDIUM 5.0
CVE-2013-5182

Mail in Apple Mac OS X before 10.9 allows remote attackers to spoof the existence of a cryptographic signature for an e-mail message by using the mul…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Iphone Os MEDIUM 6.4
CVE-2012-3732

Mail in Apple iOS before 6 uses an S/MIME message's From address as the displayed sender address, which allows remote attackers to spoof signed conte…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Mac Os X MEDIUM 6.4
CVE-2012-0655

libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for re…

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Safari MEDIUM 5.0
CVE-2011-0214

CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote w…

Fix: after 5.0.5
Fix from $1,600 2011-07-21
Mac Os X MEDIUM 5.0
CVE-2011-0207

The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows re…

Patch available
Fix from $1,600 2011-06-24
Safari MEDIUM 5.0
CVE-2010-3804EPSS 9%

The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, us…

Fix: after 5.0.2
Fix from $1,600 2010-11-22
Mac Os X HIGH 9.3
CVE-2010-1377

Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attac…

Patch available
Fix from $1,950 2010-06-17
Safari MEDIUM 5.0
CVE-2010-1413

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in …

Fix: after 4.0.5
Fix from $1,600 2010-06-11
Mac Os X MEDIUM 5.0
CVE-2010-0525

Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certif…

Fix: after 10.6.2
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 5.0
CVE-2009-2843

Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers …

Patch available
Fix from $1,600 2009-12-08
Mac Os X MEDIUM 5.4
CVE-2009-2808

Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-…

Fix: after 10.6.1
Fix from $1,600 2009-11-10
Safari HIGH 7.5
CVE-2009-3455

Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field o…

Fix: after 4.0.2
Fix from $1,950 2009-09-29
Iphone Os HIGH 7.5
CVE-2009-3273

iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof…

Mitigation only
Fix from $1,950 2009-09-21
Safari MEDIUM 5.0
CVE-2009-1696

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in Jav…

Fix: after 4.0_beta
Fix from $1,600 2009-06-10
Iphone Os HIGH 7.5
CVE-2008-4227

Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level th…

Mitigation only
Fix from $1,950 2008-11-25
Mac Os X MEDIUM 5.0
CVE-2008-4368

The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE…

Mitigation only
Fix from $1,600 2008-10-01
Mac Os X HIGH 9.3
CVE-2007-5863EPSS 23%

Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the clie…

Mitigation only
Fix from $1,950 2007-12-19