|
2961
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…
|
CWE-399
Resource Management Errors
|
CVE-2015-1069
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-03-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2962
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…
|
CWE-399
Resource Management Errors
|
CVE-2015-1068
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-03-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2963
|
-
5.4
|
MEDIUM
|
Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data str…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1065
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.3
|
|
|
2024-11-21 11:24
2015-03-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2964
|
-
1.9
|
LOW
|
Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended activation requirement and read the home screen by leveraging an application crash during the activatio…
|
CWE-200
Information Exposure
|
CVE-2015-1064
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.3
|
|
|
2024-11-21 11:24
2015-03-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2965
|
-
7.8
|
HIGH
|
CoreTelephony in Apple iOS before 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a Class 0 SMS message.
|
NVD-CWE-Other
|
CVE-2015-1063
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.3
|
|
|
2024-11-21 11:24
2015-03-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2966
|
-
5.0
|
MEDIUM
|
MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a craft…
|
CWE-19
Data Processing Errors
|
CVE-2015-1062
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.3
|
|
|
2024-11-21 11:24
2015-03-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2967
|
-
9.3
|
HIGH
|
IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confus…
|
CWE-94
Code Injection
|
CVE-2015-1061
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.3
|
|
|
2024-11-21 11:24
2015-03-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2968
|
-
4.3
|
MEDIUM
|
Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct c…
|
CWE-310
Cryptographic Issues
|
CVE-2015-1067
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.3
|
|
|
2024-11-21 11:24
2015-03-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2969
|
-
6.8
|
MEDIUM
|
The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirection of an SSL URL to the iTunes Store.
|
CWE-310
Cryptographic Issues
|
CVE-2014-8840
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:19
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2970
|
-
5.0
|
MEDIUM
|
The mach_port_kobject interface in the kernel in Apple iOS before 8.1.3 and Apple TV before 7.0.3 does not properly restrict kernel-address and heap-permutation information, which makes it easier for…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4496
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|