Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tvos MEDIUM 6.8
CVE-2014-1293

WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memo…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Tvos MEDIUM 6.8
CVE-2014-1294

WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memo…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1282

The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requireme…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.8
CVE-2014-1285

Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveragi…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.0
CVE-2014-1276

IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that acce…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.0
CVE-2014-1286

SpringBoard Lock Screen in Apple iOS before 7.1 allows remote attackers to cause a denial of service (lock-screen hang) by leveraging a state-managem…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os HIGH 8.8
CVE-2013-5133

Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via c…

Fix: after 7.0.6
Fix from $1,950 2014-03-14
Iphone Os HIGH 7.8
CVE-2014-1271

CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of s…

Fix: after 7.0.6
Fix from $1,950 2014-03-14
Tvos MEDIUM 6.3
CVE-2014-1272

CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by lever…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1267

The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile confi…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1273

dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing requirements by leveraging use of text-relocation instru…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.0
CVE-2013-6835EPSS 7%

TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remot…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Mac Os X MEDIUM 6.6
CVE-2014-0106

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local…

Fix: after 10.10.4
Fix from $1,600 2014-03-11
Mac Os X MEDIUM 6.4
CVE-2014-2234

A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL ha…

Fix: after 10.9.2
Fix from $1,600 2014-03-05
Mac Os X HIGH 7.5
CVE-2014-1262

Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages that …

Fix: after 10.9.1
Fix from $1,950 2014-02-27
Safari MEDIUM 6.8
CVE-2014-1268

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.1
Fix from $1,600 2014-02-27
Safari MEDIUM 6.8
CVE-2014-1269

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.1
Fix from $1,600 2014-02-27
Safari MEDIUM 6.8
CVE-2014-1270

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.1
Fix from $1,600 2014-02-27
Mac Os X HIGH 7.5
CVE-2014-1255

Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free function, which allows attackers to bypass the App…

Fix: after 10.9.1
Fix from $1,950 2014-02-27
Mac Os X HIGH 7.5
CVE-2014-1256

Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted …

Fix: after 10.9.1
Fix from $1,950 2014-02-27
Mac Os X HIGH 7.5
CVE-2014-1261

Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (appl…

Fix: after 10.9.1
Fix from $1,950 2014-02-27
Mac Os X MEDIUM 6.8
CVE-2014-1254

Apple Type Services (ATS) in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupti…

Fix: after 10.9.1
Fix from $1,600 2014-02-27
Mac Os X MEDIUM 6.8
CVE-2014-1258

Heap-based buffer overflow in CoreAnimation in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of servic…

Fix: after 10.9.1
Fix from $1,600 2014-02-27
Mac Os X MEDIUM 6.8
CVE-2014-1259

Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application cra…

Fix: after 10.9.1
Fix from $1,600 2014-02-27
Mac Os X MEDIUM 6.8
CVE-2014-1260

QuickLook in Apple OS X through 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicat…

Fix: after 10.8.5
Fix from $1,600 2014-02-27
Iphone Os HIGH 7.4
CVE-2014-1266EPSS 6%

The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component …

Fix: 6.0.2 / 6.1.6+
Fix from $1,950 2014-02-22
Pages HIGH 7.5
CVE-2014-1252

Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of ser…

Fix: after 10.9.1
Fix from $1,950 2014-01-24
Itunes MEDIUM 5.8
CVE-2014-1242

Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control ov…

Fix: after 11.1.3
Fix from $1,600 2014-01-23
Safari MEDIUM 6.8
CVE-2013-5198

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Safari MEDIUM 6.8
CVE-2013-5199

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18