Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tvos MEDIUM 5.8
CVE-2014-4378

CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive information or cause a denial of service (out-of…

Fix: after 10.9.4
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.5
CVE-2014-4373

The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of se…

Fix: after 10.9.5
Fix from $1,600 2014-09-18
Mac Os X MEDIUM 5.0
CVE-2014-4374

NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in co…

Fix: after 10.9.4
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.8
CVE-2014-4354

Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass intended access restrictions vi…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.6
CVE-2014-4364

The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to cal…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.0
CVE-2014-4361

The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, which allows attackers to deter…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.0
CVE-2014-4362

The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to o…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Safari MEDIUM 5.0
CVE-2014-4363

Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive info…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.0
CVE-2014-4366

Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Safari MEDIUM 6.8
CVE-2014-1384

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1385

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1386

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1387

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1388

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1389

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1390

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Mac Os X HIGH 10.0
CVE-2014-1373

Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitr…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1376

Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call, which allows attackers to execute arbitrary code…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1377

Array index error in IOAcceleratorFamily in Apple OS X before 10.9.4 allows attackers to execute arbitrary code via a crafted application.

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1379

Graphics Drivers in Apple OS X before 10.9.4 allows attackers to gain privileges or cause a denial of service (NULL pointer dereference and system cr…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1381

Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2014-07-01
Mac Os X HIGH 7.5
CVE-2014-1371

Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-poi…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Safari MEDIUM 6.8
CVE-2014-1367

WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to exec…

Fix: after 7.1.1
Fix from $1,600 2014-07-01
Safari MEDIUM 6.8
CVE-2014-1368

WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to exec…

Fix: after 7.1.1
Fix from $1,600 2014-07-01
Mac Os X MEDIUM 6.8
CVE-2014-1370

The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of servi…

Fix: after 10.9.3
Fix from $1,600 2014-07-01
Safari MEDIUM 6.8
CVE-2014-1382

WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to exec…

Fix: after 7.1.1
Fix from $1,600 2014-07-01
Tvos MEDIUM 5.5
CVE-2014-1383

Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspeci…

Fix: after 6.1.1
Fix from $1,600 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1356

Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbi…

Fix: after 7.1.1
Fix from $1,950 2014-07-01
Tvos HIGH 10.0
CVE-2014-1357

Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbi…

Fix: after 7.1.1
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1358

Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code…

Fix: after 7.1.1
Fix from $1,950 2014-07-01