Vulnerability index

Browse CVEs

365 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Quicktime Mpeg 2 Playback Component HIGH 7.6
CVE-2009-0008

Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2009-01-22
Safari HIGH 7.1
CVE-2009-0123

Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vector…

No fix yet
Fix from $1,950 2009-01-15
Safari HIGH 9.3
CVE-2009-0070

Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (appli…

No fix yet
Fix from $1,950 2009-01-08
Safari MEDIUM 5.0
CVE-2008-5821

Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory c…

No fix yet
Fix from $1,600 2009-01-02
Itunes HIGH 9.3
CVE-2008-5406EPSS 10%

Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application cra…

No fix yet
Fix from $1,950 2008-12-10
Cups MEDIUM 6.9
CVE-2008-5377

pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulner…

No fix yet
Fix from $1,600 2008-12-08
Iphone Configuration Web Utility HIGH 7.8
CVE-2008-5315

Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbit…

Mitigation only
Fix from $1,950 2008-12-03
Safari HIGH 9.3
CVE-2008-4231EPSS 6%

Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows rem…

Mitigation only
Fix from $1,950 2008-11-25
Iphone Os HIGH 7.5
CVE-2008-4227

Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level th…

Mitigation only
Fix from $1,950 2008-11-25
Iphone Os HIGH 7.1
CVE-2008-1586

ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory c…

Mitigation only
Fix from $1,950 2008-11-25
Safari MEDIUM 5.0
CVE-2008-4232

Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundarie…

Mitigation only
Fix from $1,600 2008-11-25
Mail MEDIUM 5.0
CVE-2008-4491

Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email s…

Mitigation only
Fix from $1,600 2008-10-08
Mac Os X MEDIUM 5.0
CVE-2008-4368

The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE…

Mitigation only
Fix from $1,600 2008-10-01
Mac Os X HIGH 9.3
CVE-2008-3638

Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary pro…

Mitigation only
Fix from $1,950 2008-09-26
Mac Os X HIGH 8.8
CVE-2008-3637EPSS 6%

The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, whic…

Mitigation only
Fix from $1,950 2008-09-26
Itunes HIGH 9.3
CVE-2008-4116EPSS 12%

Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbi…

No fix yet
Fix from $1,950 2008-09-18
Ipod Touch HIGH 7.1
CVE-2008-3631

Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which al…

Mitigation only
Fix from $1,950 2008-09-11
Safari MEDIUM 6.8
CVE-2008-3170

Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to …

Mitigation only
Fix from $1,600 2008-07-14
Safari MEDIUM 5.0
CVE-2008-3171

Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive …

Mitigation only
Fix from $1,600 2008-07-14
Safari HIGH 10.0
CVE-2008-2303EPSS 13%

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a …

Mitigation only
Fix from $1,950 2008-07-14
Safari HIGH 9.3
CVE-2008-2317EPSS 8%

WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-07-14
Mac Os X HIGH 7.2
CVE-2008-2830

Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of sc…

No fix yet
Fix from $1,950 2008-06-23
Mac Os X HIGH 10.0
CVE-2008-1030

Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent atta…

Mitigation only
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1028

Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial o…

Mitigation only
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1031EPSS 6%

CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

Mitigation only
Fix from $1,950 2008-06-02
Safari MEDIUM 5.0
CVE-2008-1999

Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the author…

Mitigation only
Fix from $1,600 2008-04-28
Safari MEDIUM 6.8
CVE-2008-1024

Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arb…

Mitigation only
Fix from $1,600 2008-04-17
Safari MEDIUM 6.8
CVE-2008-0894

Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitm…

Mitigation only
Fix from $1,600 2008-02-21
Iphoto HIGH 7.5
CVE-2008-0830

The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: U…

No fix yet
Fix from $1,950 2008-02-19
Mobile Safari HIGH 7.1
CVE-2008-0729EPSS 8%

Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain J…

No fix yet
Fix from $1,950 2008-02-12