Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2014-4466 WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de… Safari after 12.1 Fix from $1,9502014-12-10 MEDIUM 5.0 CVE-2014-4465 WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Casc… Safari after 8.1.2 Fix from $1,6002014-12-10 MEDIUM 5.8 CVE-2014-4462 WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (… Iphone Os after 8.1 Fix from $1,6002014-11-18 HIGH 9.3 CVE-2014-4461 The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers t… Iphone Os after 10.10.1 Fix from $1,9502014-11-18 MEDIUM 6.8 CVE-2014-4459 Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page obje… Safari 6.2.1 / 7.0.3+ Fix from $1,6002014-11-18 MEDIUM 5.0 CVE-2014-4458 The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might all… Mac Os X after 10.10.0 Fix from $1,6002014-11-18 HIGH 7.5 CVE-2014-4457 The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intend… Iphone Os after 8.1 Fix from $1,9502014-11-18 MEDIUM 5.0 CVE-2014-4453 Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight o… Iphone Os after 10.10.0 Fix from $1,6002014-11-18 MEDIUM 5.4 CVE-2014-4452 WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (… Safari 6.2.1 / 7.0.2+ Fix from $1,6002014-11-18 HIGH 7.2 CVE-2014-4451 Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lo… Iphone Os after 8.1 Fix from $1,9502014-11-18 HIGH 7.5 CVE-2014-8517EPSS 69% The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.… Mac Os X Patch available Fix from $1,9502014-11-17 MEDIUM 6.8 CVE-2014-4449 iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser… Iphone Os after 8.0.2 Fix from $1,6002014-10-22 HIGH 7.8 CVE-2014-4443 Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.1 data. Mac Os X after 10.9.5 Fix from $1,9502014-10-18 HIGH 7.5 CVE-2014-4427 App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API. Mac Os X after 10.9.5 Fix from $1,9502014-10-18 HIGH 7.2 CVE-2014-4433 Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arbitrary code via crafted resou… Mac Os X after 10.9.5 Fix from $1,9502014-10-18 MEDIUM 6.9 CVE-2014-4438 Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstati… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 6.8 CVE-2014-4437 LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application that specifies a crafted handle… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 6.8 CVE-2014-4441 NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attacker… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 5.4 CVE-2014-4428 Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by lever… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 6.8 CVE-2014-4351 Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a denial of service (application c… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 6.8 CVE-2014-4391 The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bundles, which allows remote att… Mac Os X after 10.9.4 Fix from $1,6002014-10-18 MEDIUM 5.0 CVE-2014-4417 Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outage) via a web site that trigg… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 HIGH 9.3 CVE-2014-7861 The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code… Mac Os X Mitigation only Fix from $1,9502014-10-05 HIGH 7.5 CVE-2014-4424 SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to exe… Os X Server after 2.2.2 Fix from $1,9502014-09-19 MEDIUM 6.9 CVE-2014-4416 An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls… Mac Os X Mitigation only Fix from $1,6002014-09-19 MEDIUM 6.1 CVE-2014-4406 Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arb… Os X Server after 3.1.2 Fix from $1,6002014-09-19 HIGH 10.0 CVE-2014-4376 IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of serv… Mac Os X Mitigation only Fix from $1,9502014-09-19 HIGH 10.0 CVE-2014-4393EPSS 6% Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 allows remote attackers to execute arbitrar… Mac Os X Mitigation only Fix from $1,9502014-09-19 HIGH 9.3 CVE-2014-4390 Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context … Mac Os X Mitigation only Fix from $1,9502014-09-19 HIGH 9.3 CVE-2014-4402 An unspecified IOAcceleratorFamily function in Apple OS X before 10.9.5 lacks proper bounds checking on read operations, which allows attackers to ex… Mac Os X Mitigation only Fix from $1,9502014-09-19