Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.5
CVE-2009-2191

Format string vulnerability in Login Window in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows attackers to execute arbitrary code or cause a de…

Patch available
Fix from $1,950 2009-08-06
Mac Os X HIGH 7.5
CVE-2009-2192

MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for a…

Patch available
Fix from $1,950 2009-08-06
Mac Os X MEDIUM 6.8
CVE-2009-1727

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute ar…

Patch available
Fix from $1,600 2009-08-06
Mac Os X MEDIUM 6.8
CVE-2009-1728EPSS 6%

Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows re…

Patch available
Fix from $1,600 2009-08-06
Mac Os X HIGH 7.2
CVE-2009-0151

The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate at…

Patch available
Fix from $1,950 2009-08-06
Iphone Os HIGH 10.0
CVE-2009-2204EPSS 8%

Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GP…

Fix: after 3.0
Fix from $1,950 2009-08-03
Safari HIGH 9.3
CVE-2009-1725EPSS 6%

WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in…

Fix: after 4.0.1
Fix from $1,950 2009-07-09
Safari MEDIUM 5.8
CVE-2009-2420

Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of…

Mitigation only
Fix from $1,600 2009-07-09
Safari MEDIUM 5.0
CVE-2009-2421

The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL poin…

Mitigation only
Fix from $1,600 2009-07-09
Iphone Os HIGH 7.8
CVE-2009-1683

The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial…

Patch available
Fix from $1,950 2009-06-19
Iphone Os HIGH 7.1
CVE-2009-0959

The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial …

Patch available
Fix from $1,950 2009-06-19
Safari HIGH 7.1
CVE-2009-1692

WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows re…

No fix yet
Fix from $1,950 2009-06-19
Iphone Os MEDIUM 5.0
CVE-2009-0961EPSS 6%

The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when anothe…

Patch available
Fix from $1,600 2009-06-19
Safari MEDIUM 6.8
CVE-2009-2058

Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a p…

Fix: after 3.2.2
Fix from $1,600 2009-06-15
Safari MEDIUM 6.8
CVE-2009-2062

Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execut…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Safari MEDIUM 6.8
CVE-2009-2066

Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute ar…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Safari MEDIUM 5.4
CVE-2009-2072

Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to s…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Safari HIGH 7.2
CVE-2009-2027

The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the…

Fix: after 3.2.3
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1698EPSS 8%

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during h…

Fix: after 3.2.2
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1701EPSS 8%

Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS fo…

Fix: after 3.2.2
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1704

CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote a…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1705EPSS 5%

CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote a…

Fix: after 3.2.3
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1708EPSS 5%

Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary loca…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1709EPSS 7%

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to exec…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1711EPSS 7%

WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code o…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1712EPSS 8%

WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gai…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 7.5
CVE-2009-1699EPSS 29%

The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 d…

Fix: 4.0+
Fix from $1,950 2009-06-10
Safari HIGH 7.1
CVE-2009-1703

WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 7.1
CVE-2009-1713

The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read …

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 7.1
CVE-2009-1718

WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dra…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10