Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
iOS Number Of NVD 3541 CRITICAL 137 HIGH 1622 MEDIUM 1441 LOW 245
URL https://www.apple.com/jp/ios/
Explanation This is the operating system installed on the iPhone provided by Apple.
Tag
  • Mobile
  • Apple

Add Information URL
No Type Name URL
1 https://support.apple.com/en-us/HT201222
2 https://developer.apple.com/documentation/ios-ipados-release-notes
3 https://en.wikipedia.org/wiki/IOS_version_history

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
3001 iOS17 17.6.1 Aug. 27, 2024 Sept. 18, 2023 8 70 139 21
3002 iOS16 16.4.1 April 7, 2023 Sept. 12, 2022 24 200 264 55
3003 iOS 15 15.7 Sept. 12, 2022 Sept. 20, 2021 38 351 349 71
3004 iOS 14 14.8 Sept. 13, 2021 July 9, 2020 52 522 456 78
3005 iOS 13 13.7 Sept. 1, 2020 Sept. 19, 2019 64 702 540 95
3006 iOS 12 12.5.1 Jan. 11, 2021 Sept. 17, 2018 83 859 620 107
3007 iOS 11 11.4.1 July 9, 2018 Sept. 19, 2017 93 1024 689 115
3008 iOS 10 10.3.4 July 22, 2019 Sept. 13, 2016 119 1245 789 132
3009 iOS 9 9.3.6 July 22, 2019 Sept. 16, 2015 133 1371 916 148
3010 iOS 8 8.4.1 Aug. 13, 2015 Sept. 17, 2014 131 1426 1129 180
3011 iOS 7 7.0.6 Feb. 21, 2014 Sept. 18, 2013 131 1447 1192 203
3012 iOS 6 6.0.2 Dec. 18, 2012 Sept. 19, 2012 131 1473 1255 215
3013 iOS 5 5.0.1 Nov. 10, 2011 Oct. 12, 2011 131 1542 1329 227
3014 iOS 4 4.0.2 Aug. 11, 2010 June 21, 2010 132 1569 1384 234
3015 iPhone OS 3 3.0.1 July 31, 2009 June 17, 2009 132 1576 1399 237
3016 iPhone OS 2 1.1.5 July 15, 2008 July 11, 2008 133 1588 1394 235
3017 iPhone OS 1 1.0.2 Aug. 21, 2007 June 29, 2007 132 1593 1395 236
3018 iOS7.1 7.1.2 131 1440 1168 197
3019 iOS6.1 6.1.6 131 1464 1236 211
3020 iOS6.0 6.0.2 131 1473 1254 215
3021 iOS5.1 5.1.1 131 1483 1307 225
3022 iOS4.3 4.3.5 131 1561 1357 233
3023 iOS4.2 4.2.9 131 1563 1362 233
3024 iOS4.1 4.1 132 1566 1374 233
3025 iOS3.2 3.2.2 132 1570 1389 235
3026 iOS3.1 3.1.3 132 1573 1397 235
3027 iOS2.2 2.2.1 132 1584 1393 231
3028 iOS2.1 2.1.1 132 1588 1394 235
3029 iOS2.0 2.0.2 133 1588 1393 235
3030 iOS16.2 16.2 18 165 231 54
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
3001 -
9.3
HIGH The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context v… CWE-20
 Improper Input Validation 
CVE-2014-4461 cpe:2.3:o:apple:iphone_os:8.0:*
cpe:2.3:o:apple:iphone_os:8.0.2:*
cpe:2.3:o:apple:iphone_os:8.0.1:*
cpe:2.3:o:…
8.1 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3002 -
2.1
LOW CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate a… CWE-200
Information Exposure
CVE-2014-4460 cpe:2.3:o:apple:iphone_os:8.0:*
cpe:2.3:o:apple:iphone_os:8.0.2:*
cpe:2.3:o:apple:iphone_os:8.0.1:*
cpe:2.3:o:…
8.1 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3003 -
6.8
MEDIUM Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document. NVD-CWE-Other
CVE-2014-4459 cpe:2.3:o:apple:iphone_os:*:* 8.1.3 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3004 -
7.5
HIGH The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted app… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-4457 cpe:2.3:o:apple:iphone_os:8.0:*
cpe:2.3:o:apple:iphone_os:8.0.2:*
cpe:2.3:o:apple:iphone_os:8.0.1:*
cpe:2.3:o:…
8.1 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3005 -
2.1
LOW dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restriction… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-4455 cpe:2.3:o:apple:iphone_os:*:* 8.1.2 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3006 -
5.0
MEDIUM Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to ob… CWE-200
Information Exposure
CVE-2014-4453 cpe:2.3:o:apple:iphone_os:8.0:*
cpe:2.3:o:apple:iphone_os:8.0.2:*
cpe:2.3:o:apple:iphone_os:8.0.1:*
cpe:2.3:o:…
8.1 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3007 -
5.4
MEDIUM WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cra… CWE-399
 Resource Management Errors
CVE-2014-4452 cpe:2.3:o:apple:iphone_os:*:* 8.0 8.1.1 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3008 -
7.2
HIGH Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lock-screen protection mechanism via a series of gue… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-4451 cpe:2.3:o:apple:iphone_os:8.0:*
cpe:2.3:o:apple:iphone_os:8.0.2:*
cpe:2.3:o:apple:iphone_os:8.0.1:*
cpe:2.3:o:…
8.1 2024-11-21 11:10
2014-11-18
Show GitHub Exploit DB Packet Storm
3009 -
1.9
LOW The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discove… CWE-255
Credentials Management
CVE-2014-4450 cpe:2.3:o:apple:iphone_os:*:* 8.0.2 2024-11-21 11:10
2014-10-22
Show GitHub Exploit DB Packet Storm
3010 -
6.8
MEDIUM iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte… CWE-310
Cryptographic Issues
CVE-2014-4449 cpe:2.3:o:apple:iphone_os:*:* 8.0.2 2024-11-21 11:10
2014-10-22
Show GitHub Exploit DB Packet Storm