Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari HIGH 9.3
CVE-2012-3594

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and app…

Fix: after 5.1.7
Fix from $1,950 2012-07-25
Safari HIGH 8.8
CVE-2012-3590

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and app…

Fix: after 5.1.7
Fix from $1,950 2012-07-25
Safari HIGH 7.1
CVE-2012-3697

WebKit in Apple Safari before 6.0 does not properly handle file: URLs, which allows remote attackers to bypass intended sandbox restrictions and read…

Fix: after 5.1.7
Fix from $1,950 2012-07-25
Safari MEDIUM 5.8
CVE-2012-3689

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origi…

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Safari MEDIUM 5.8
CVE-2012-3691

WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the …

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Safari MEDIUM 5.0
CVE-2012-3693

Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to spoof domain names in URLs, and possibly conduct p…

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Safari MEDIUM 5.0
CVE-2012-0680

Apple Safari before 6.0 does not properly handle the autocomplete attribute of a password input element, which allows remote attackers to bypass auth…

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Itunes HIGH 9.3
CVE-2012-0677EPSS 15%

Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application …

Fix: after 10.6.1
Fix from $1,950 2012-06-12
Mac Os X HIGH 7.5
CVE-2012-0662

Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of ser…

Fix: after 10.7.3
Fix from $1,950 2012-05-11
Mac Os X MEDIUM 6.8
CVE-2012-0658

Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (applicat…

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 6.8
CVE-2012-0659

Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (applica…

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 6.8
CVE-2012-0660

Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (applica…

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 6.8
CVE-2012-0661

Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,600 2012-05-11
Safari MEDIUM 5.0
CVE-2012-0676

WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to f…

Fix: after 5.1.6
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 6.9
CVE-2012-0649

Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors …

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 6.9
CVE-2012-0656

Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers t…

Mitigation only
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 6.8
CVE-2012-0654

libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote …

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 6.4
CVE-2012-0655

libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for re…

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Mac Os X MEDIUM 5.0
CVE-2012-0651

The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a …

Mitigation only
Fix from $1,600 2012-05-11
Iphone Os MEDIUM 6.8
CVE-2012-0672

WebKit in Apple iOS before 5.1.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application cr…

Fix: after 5.1
Fix from $1,600 2012-05-08
Safari MEDIUM 6.4
CVE-2012-0584

The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allo…

Fix: after 5.1.2
Fix from $1,600 2012-03-12
Safari MEDIUM 5.0
CVE-2012-0640

WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remot…

Fix: after 5.1.3
Fix from $1,600 2012-03-12
Safari MEDIUM 5.0
CVE-2012-0647

WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers …

Fix: after 5.1.3
Fix from $1,600 2012-03-12
Iphone Os HIGH 9.3
CVE-2012-0642

Integer underflow in Apple iOS before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (device crash) via a crafted…

Fix: 5.1+
Fix from $1,950 2012-03-08
Iphone Os HIGH 9.3
CVE-2012-0643

The kernel in Apple iOS before 5.1 does not properly handle debug system calls, which allows remote attackers to bypass sandbox restrictions and exec…

Fix: 5.1+
Fix from $1,950 2012-03-08
Iphone Os HIGH 9.3
CVE-2012-0646

Format string vulnerability in VPN in Apple iOS before 5.1 allows remote attackers to execute arbitrary code via a crafted racoon configuration file.

Fix: 5.1+
Fix from $1,950 2012-03-08
Itunes HIGH 7.6
CVE-2012-0638

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corrup…

Fix: after 10.5.3
Fix from $1,950 2012-03-08
Itunes HIGH 7.6
CVE-2012-0639

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corrup…

Fix: after 10.5.3
Fix from $1,950 2012-03-08
Itunes HIGH 7.6
CVE-2012-0648

WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corrup…

Fix: after 10.5.3
Fix from $1,950 2012-03-08
Iphone Os MEDIUM 6.9
CVE-2012-0644

Race condition in the Passcode Lock feature in Apple iOS before 5.1 allows physically proximate attackers to bypass intended passcode requirements vi…

Fix: 5.1+
Fix from $1,600 2012-03-08