Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari HIGH 7.5
CVE-2014-4466

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,950 2014-12-10
Safari MEDIUM 5.0
CVE-2014-4465

WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Casc…

Fix: after 8.1.2
Fix from $1,600 2014-12-10
Iphone Os MEDIUM 5.8
CVE-2014-4462

WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (…

Fix: after 8.1
Fix from $1,600 2014-11-18
Iphone Os HIGH 9.3
CVE-2014-4461

The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers t…

Fix: after 10.10.1
Fix from $1,950 2014-11-18
Safari MEDIUM 6.8
CVE-2014-4459

Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page obje…

Fix: 6.2.1 / 7.0.3+
Fix from $1,600 2014-11-18
Mac Os X MEDIUM 5.0
CVE-2014-4458

The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might all…

Fix: after 10.10.0
Fix from $1,600 2014-11-18
Iphone Os HIGH 7.5
CVE-2014-4457

The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intend…

Fix: after 8.1
Fix from $1,950 2014-11-18
Iphone Os MEDIUM 5.0
CVE-2014-4453

Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight o…

Fix: after 10.10.0
Fix from $1,600 2014-11-18
Safari MEDIUM 5.4
CVE-2014-4452

WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (…

Fix: 6.2.1 / 7.0.2+
Fix from $1,600 2014-11-18
Iphone Os HIGH 7.2
CVE-2014-4451

Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lo…

Fix: after 8.1
Fix from $1,950 2014-11-18
Mac Os X HIGH 7.5
CVE-2014-8517EPSS 69%

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.…

Patch available
Fix from $1,950 2014-11-17
Iphone Os MEDIUM 6.8
CVE-2014-4449

iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser…

Fix: after 8.0.2
Fix from $1,600 2014-10-22
Mac Os X HIGH 7.8
CVE-2014-4443

Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.1 data.

Fix: after 10.9.5
Fix from $1,950 2014-10-18
Mac Os X HIGH 7.5
CVE-2014-4427

App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.

Fix: after 10.9.5
Fix from $1,950 2014-10-18
Mac Os X HIGH 7.2
CVE-2014-4433

Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arbitrary code via crafted resou…

Fix: after 10.9.5
Fix from $1,950 2014-10-18
Mac Os X MEDIUM 6.9
CVE-2014-4438

Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstati…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4437

LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application that specifies a crafted handle…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4441

NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attacker…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 5.4
CVE-2014-4428

Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by lever…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4351

Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a denial of service (application c…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4391

The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bundles, which allows remote att…

Fix: after 10.9.4
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 5.0
CVE-2014-4417

Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outage) via a web site that trigg…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X HIGH 9.3
CVE-2014-7861

The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2014-10-05
Os X Server HIGH 7.5
CVE-2014-4424

SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to exe…

Fix: after 2.2.2
Fix from $1,950 2014-09-19
Mac Os X MEDIUM 6.9
CVE-2014-4416

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls…

Mitigation only
Fix from $1,600 2014-09-19
Os X Server MEDIUM 6.1
CVE-2014-4406

Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arb…

Fix: after 3.1.2
Fix from $1,600 2014-09-19
Mac Os X HIGH 10.0
CVE-2014-4376

IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of serv…

Mitigation only
Fix from $1,950 2014-09-19
Mac Os X HIGH 10.0
CVE-2014-4393EPSS 6%

Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2014-09-19
Mac Os X HIGH 9.3
CVE-2014-4390

Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context …

Mitigation only
Fix from $1,950 2014-09-19
Mac Os X HIGH 9.3
CVE-2014-4402

An unspecified IOAcceleratorFamily function in Apple OS X before 10.9.5 lacks proper bounds checking on read operations, which allows attackers to ex…

Mitigation only
Fix from $1,950 2014-09-19