|
2971
|
-
10.0
|
HIGH
|
The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4495
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2972
|
-
6.8
|
MEDIUM
|
Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, which allows attackers to bypass intended first-la…
|
CWE-20
Improper Input Validation
|
CVE-2014-4494
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2973
|
-
7.5
|
HIGH
|
The app-installation functionality in MobileInstallation in Apple iOS before 8.1.3 allows attackers to obtain control of the local app container by leveraging access to an enterprise distribution cer…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4493
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2974
|
-
7.5
|
HIGH
|
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary…
|
CWE-19
Data Processing Errors
|
CVE-2014-4492
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2975
|
-
5.0
|
MEDIUM
|
The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addresses within an OSBundleMachOHeaders key in a respo…
|
CWE-200
Information Exposure
|
CVE-2014-4491
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2976
|
-
10.0
|
HIGH
|
IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly initialize event queues, which allows attackers to execute arbitrary code in a privileged…
|
NVD-CWE-Other
|
CVE-2014-4489
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2977
|
-
10.0
|
HIGH
|
IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly validate resource-queue metadata, which allows attackers to execute arbitrary code in a p…
|
CWE-19
Data Processing Errors
|
CVE-2014-4488
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2978
|
-
10.0
|
HIGH
|
Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows attackers to execute arbitrary code in a privileged context via a crafted app.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4487
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2979
|
-
10.0
|
HIGH
|
IOAcceleratorFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly handle resource lists and IOService userclient types, which allows attackers to e…
|
NVD-CWE-Other
|
CVE-2014-4486
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2980
|
-
7.5
|
HIGH
|
Buffer overflow in the XML parser in Foundation in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4485
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2015-01-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|