Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Itunes HIGH 7.6
CVE-2011-0123

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0124

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0125

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0126

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0127

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0128

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0129

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0130

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0131

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Safari HIGH 7.6
CVE-2011-0132

Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit,…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Itunes HIGH 7.6
CVE-2011-0133

WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Mac Os X MEDIUM 6.9
CVE-2011-0639

Apple Mac OS X does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assi…

Mitigation only
Fix from $1,600 2011-01-25
Mac Os X MEDIUM 6.8
CVE-2010-4013

Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or caus…

Patch available
Fix from $1,600 2011-01-10
Airport Express Base Station Firmware HIGH 7.1
CVE-2010-1804

Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Stati…

Fix: after 7.4.2
Fix from $1,950 2010-12-22
Airport Express Base Station Firmware MEDIUM 6.1
CVE-2009-2189

The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does n…

Fix: after 7.4.2
Fix from $1,600 2010-12-22
Iphone Os MEDIUM 6.2
CVE-2010-4012

Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a cal…

Mitigation only
Fix from $1,600 2010-12-08
Iphone Os HIGH 7.2
CVE-2010-3830

Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privile…

Fix: after 4.1
Fix from $1,950 2010-11-26
Iphone Os MEDIUM 6.8
CVE-2010-3832

Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote at…

Fix: after 4.1
Fix from $1,600 2010-11-26
Iphone Os MEDIUM 5.8
CVE-2010-3829

WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetc…

Fix: after 4.1
Fix from $1,600 2010-11-26
Safari HIGH 9.3
CVE-2010-3822

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses an uninitialized pointer d…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3823EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, all…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3824EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, all…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3826

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3808

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3809

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3811EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, all…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3812EPSS 7%

Integer overflow in the Text::wholeText method in dom/Text.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Wind…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3816EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, all…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3817

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3818EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, all…

Fix: after 5.0.2
Fix from $1,950 2010-11-22