|
3001
|
-
9.3
|
HIGH
|
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context v…
|
CWE-20
Improper Input Validation
|
CVE-2014-4461
|
cpe:2.3:o:apple:iphone_os:8.0:* cpe:2.3:o:apple:iphone_os:8.0.2:* cpe:2.3:o:apple:iphone_os:8.0.1:* cpe:2.3:o:…
|
|
8.1
|
|
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3002
|
-
2.1
|
LOW
|
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate a…
|
CWE-200
Information Exposure
|
CVE-2014-4460
|
cpe:2.3:o:apple:iphone_os:8.0:* cpe:2.3:o:apple:iphone_os:8.0.2:* cpe:2.3:o:apple:iphone_os:8.0.1:* cpe:2.3:o:…
|
|
8.1
|
|
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3003
|
-
6.8
|
MEDIUM
|
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
|
NVD-CWE-Other
|
CVE-2014-4459
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
8.1.3
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3004
|
-
7.5
|
HIGH
|
The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted app…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4457
|
cpe:2.3:o:apple:iphone_os:8.0:* cpe:2.3:o:apple:iphone_os:8.0.2:* cpe:2.3:o:apple:iphone_os:8.0.1:* cpe:2.3:o:…
|
|
8.1
|
|
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3005
|
-
2.1
|
LOW
|
dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restriction…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4455
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.1.2
|
|
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3006
|
-
5.0
|
MEDIUM
|
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to ob…
|
CWE-200
Information Exposure
|
CVE-2014-4453
|
cpe:2.3:o:apple:iphone_os:8.0:* cpe:2.3:o:apple:iphone_os:8.0.2:* cpe:2.3:o:apple:iphone_os:8.0.1:* cpe:2.3:o:…
|
|
8.1
|
|
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3007
|
-
5.4
|
MEDIUM
|
WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cra…
|
CWE-399
Resource Management Errors
|
CVE-2014-4452
|
cpe:2.3:o:apple:iphone_os:*:*
|
8.0
|
|
|
8.1.1
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3008
|
-
7.2
|
HIGH
|
Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lock-screen protection mechanism via a series of gue…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4451
|
cpe:2.3:o:apple:iphone_os:8.0:* cpe:2.3:o:apple:iphone_os:8.0.2:* cpe:2.3:o:apple:iphone_os:8.0.1:* cpe:2.3:o:…
|
|
8.1
|
|
|
2024-11-21 11:10
2014-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3009
|
-
1.9
|
LOW
|
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discove…
|
CWE-255
Credentials Management
|
CVE-2014-4450
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.0.2
|
|
|
2024-11-21 11:10
2014-10-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3010
|
-
6.8
|
MEDIUM
|
iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte…
|
CWE-310
Cryptographic Issues
|
CVE-2014-4449
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.0.2
|
|
|
2024-11-21 11:10
2014-10-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|