Vulnerability index

Browse CVEs

365 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Safari HIGH 7.6
CVE-2011-3845

Use-after-free vulnerability in Apple Safari 5.1.2, when a plug-in with a blocking function is installed, allows user-assisted remote attackers to ex…

Mitigation only
Fix from $1,950 2012-03-08
Mac Os X HIGH 7.2
CVE-2011-3463

WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by levera…

Mitigation only
Fix from $1,950 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3450

CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arb…

Mitigation only
Fix from $1,600 2012-02-02
Safari MEDIUM 5.0
CVE-2010-5070

The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle…

No fix yet
Fix from $1,600 2011-12-07
Mac Os X HIGH 7.6
CVE-2008-7303

The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attack…

No fix yet
Fix from $1,950 2011-11-15
Mac Os X HIGH 7.6
CVE-2011-1516

The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all crea…

No fix yet
Fix from $1,950 2011-11-15
Iphone Os HIGH 7.2
CVE-2011-3442

The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute a…

Mitigation only
Fix from $1,950 2011-11-11
Mac Os X MEDIUM 6.8
CVE-2011-3437

Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a cr…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.5
CVE-2011-3436

Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allo…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os HIGH 9.3
CVE-2011-3430

The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement local…

No fix yet
Fix from $1,950 2011-10-14
Iphone Os MEDIUM 6.8
CVE-2011-3260

Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application cra…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os MEDIUM 6.8
CVE-2011-3261

Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (appli…

Mitigation only
Fix from $1,600 2011-10-14
Apple Tv MEDIUM 5.0
CVE-2011-3259

The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remo…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os MEDIUM 5.0
CVE-2011-3432

The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3226

Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypas…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 5.0
CVE-2011-3225

The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 5.0
CVE-2011-3246

CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to …

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X HIGH 7.1
CVE-2011-2601

The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desk…

No fix yet
Fix from $1,950 2011-06-30
Iphone Os MEDIUM 5.0
CVE-2011-0159

The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari …

Mitigation only
Fix from $1,600 2011-03-11
Webkit HIGH 10.0
CVE-2011-1290EPSS 10%

Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.1…

Mitigation only
Fix from $1,950 2011-03-11
Mac Os X MEDIUM 6.9
CVE-2011-0639

Apple Mac OS X does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assi…

Mitigation only
Fix from $1,600 2011-01-25
Iphone Os MEDIUM 6.2
CVE-2010-4012

Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a cal…

Mitigation only
Fix from $1,600 2010-12-08
Itunes HIGH 9.3
CVE-2010-1795

Untrusted search path vulnerability in Apple iTunes before 9.1, when running on Windows 7, Vista, and XP, allows local users and possibly remote atta…

Mitigation only
Fix from $1,950 2010-08-20
Webkit HIGH 10.0
CVE-2010-1386

page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has un…

Mitigation only
Fix from $1,950 2010-08-19
Webkit HIGH 10.0
CVE-2010-1760

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials duri…

Mitigation only
Fix from $1,950 2010-08-19
Iphone Os HIGH 9.3
CVE-2010-1797EPSS 31%

Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in Fre…

No fix yet
Fix from $1,950 2010-08-16
Iphone Os MEDIUM 6.9
CVE-2010-2973

Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privil…

No fix yet
Fix from $1,600 2010-08-05
Iphone Os MEDIUM 5.0
CVE-2010-1226

The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of servic…

No fix yet
Fix from $1,600 2010-04-01
Mac Os X HIGH 7.5
CVE-2010-0524

The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of a…

Mitigation only
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.5
CVE-2010-0535

Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending …

Mitigation only
Fix from $1,600 2010-03-30