Vulnerability index

Browse CVEs

365 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mac Os X CRITICAL 9.8
CVE-2018-4296

This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks.

Mitigation only
Fix from $2,300 2020-10-27
Shazam HIGH 8.8
CVE-2019-8792

An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. …

Mitigation only
Fix from $1,950 2019-12-18
Iphone 3gs MEDIUM 6.8
CVE-2019-9536

Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical acc…

No fix yet
Fix from $1,600 2019-11-22
Mail MEDIUM 5.9
CVE-2017-17688EPSS 6%

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAI…

No fix yet
Fix from $1,600 2018-05-16
Mac Os X HIGH 7.8
CVE-2017-13827

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "kext tools" component. It allows attackers…

Mitigation only
Fix from $1,950 2018-04-03
Mac Os X HIGH 7.5
CVE-2017-13837

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Installer" component. It does not properly…

Mitigation only
Fix from $1,950 2018-04-03
Mac Os X MEDIUM 5.5
CVE-2017-13839

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" component. It allows local user…

Mitigation only
Fix from $1,600 2018-04-03
Mac Os X MEDIUM 5.5
CVE-2017-13851

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "DesktopServices" component. It allows loca…

Mitigation only
Fix from $1,600 2018-04-03
Safari CRITICAL 9.8
CVE-2017-17821

WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buff…

Mitigation only
Fix from $2,300 2017-12-21
Iphone Os HIGH 7.5
CVE-2017-14315

In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a t…

Mitigation only
Fix from $1,950 2017-09-12
Safari HIGH 8.8
CVE-2011-3438

WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution.

Mitigation only
Fix from $1,950 2017-04-24
Mac Os X HIGH 7.8
CVE-2010-1816

Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2017-04-13
Mac Os X HIGH 7.8
CVE-2010-1821

Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.

Mitigation only
Fix from $1,950 2017-04-13
Safari CRITICAL 9.8
CVE-2017-5949

JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based ou…

Mitigation only
Fix from $2,300 2017-04-03
Safari HIGH 7.5
CVE-2016-10222

runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial…

Mitigation only
Fix from $1,950 2017-04-03
Safari HIGH 7.5
CVE-2016-10226

JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-…

Mitigation only
Fix from $1,950 2017-04-03
Mac Os X MEDIUM 5.5
CVE-2017-6974

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the "Sys…

Mitigation only
Fix from $1,600 2017-04-02
Safari HIGH 8.8
CVE-2017-2471EPSS 9%

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS before 3.2 is affected. The i…

No fix yet
Fix from $1,950 2017-04-02
Safari MEDIUM 5.3
CVE-2016-7152EPSS 14%

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for r…

Mitigation only
Fix from $1,600 2016-09-06
Iphone Os HIGH 7.8
CVE-2016-4654

IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory…

Mitigation only
Fix from $1,950 2016-08-18
Safari MEDIUM 5.4
CVE-2016-4604

Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP por…

Mitigation only
Fix from $1,600 2016-07-22
Webkit HIGH 7.5
CVE-2016-4591

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to acces…

No fix yet
Fix from $1,950 2016-07-22
Webkit HIGH 8.8
CVE-2016-4589

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of s…

No fix yet
Fix from $1,950 2016-07-22
Webkit HIGH 8.8
CVE-2016-4588

WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted we…

No fix yet
Fix from $1,950 2016-07-22
Webkit MEDIUM 6.5
CVE-2016-4587

WebKit in Apple iOS before 9.3.3 and tvOS before 9.2.2 allows remote attackers to obtain sensitive information from uninitialized process memory via …

No fix yet
Fix from $1,600 2016-07-22
Webkit MEDIUM 6.1
CVE-2016-4585

Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.…

No fix yet
Fix from $1,600 2016-07-22
Mac Os X HIGH 9.3
CVE-2014-8835EPSS 8%

The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type,…

No fix yet
Fix from $1,950 2015-01-30
Mac Os X HIGH 9.3
CVE-2014-7861

The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2014-10-05
Mac Os X MEDIUM 6.9
CVE-2014-4416

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Mac Os X HIGH 10.0
CVE-2014-4376

IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of serv…

Mitigation only
Fix from $1,950 2014-09-19