|
3101
|
-
2.1
|
LOW
|
FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call.
|
CWE-200
Information Exposure
|
CVE-2014-1274
|
cpe:2.3:o:apple:iphone_os:7.0:* cpe:2.3:o:apple:iphone_os:7.0.5:* cpe:2.3:o:apple:iphone_os:7.0.4:* cpe:2.3:o:…
|
|
7.0.6
|
|
|
2024-11-21 11:03
2014-03-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3102
|
-
5.8
|
MEDIUM
|
dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing requirements by leveraging use of text-relocation instructions in a dynamic library.
|
CWE-20
Improper Input Validation
|
CVE-2014-1273
|
cpe:2.3:o:apple:iphone_os:7.0:* cpe:2.3:o:apple:iphone_os:7.0.5:* cpe:2.3:o:apple:iphone_os:7.0.4:* cpe:2.3:o:…
|
|
7.0.6
|
|
|
2024-11-21 11:03
2014-03-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3103
|
-
6.3
|
MEDIUM
|
CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink.
|
CWE-59
Link Following
|
CVE-2014-1272
|
cpe:2.3:o:apple:iphone_os:7.0:* cpe:2.3:o:apple:iphone_os:7.0.5:* cpe:2.3:o:apple:iphone_os:7.0.4:* cpe:2.3:o:…
|
|
7.0.6
|
|
|
2024-11-21 11:03
2014-03-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3104
|
-
7.8
|
HIGH
|
CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of service (assertion failure and device crash) via a …
|
CWE-20
Improper Input Validation
|
CVE-2014-1271
|
cpe:2.3:o:apple:iphone_os:7.0:* cpe:2.3:o:apple:iphone_os:7.0.5:* cpe:2.3:o:apple:iphone_os:7.0.4:* cpe:2.3:o:…
|
|
7.0.6
|
|
|
2024-11-21 11:03
2014-03-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3105
|
-
5.8
|
MEDIUM
|
The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass…
|
CWE-20
Improper Input Validation
|
CVE-2014-1267
|
cpe:2.3:o:apple:iphone_os:7.0:* cpe:2.3:o:apple:iphone_os:7.0.5:* cpe:2.3:o:apple:iphone_os:7.0.4:* cpe:2.3:o:…
|
|
7.0.6
|
|
|
2024-11-21 11:03
2014-03-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3106
|
-
5.0
|
MEDIUM
|
TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6835
|
cpe:2.3:o:apple:iphone_os:7.0:* cpe:2.3:o:apple:iphone_os:7.0.5:* cpe:2.3:o:apple:iphone_os:7.0.4:* cpe:2.3:o:…
|
|
7.0.6
|
|
|
2024-11-21 10:59
2014-03-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3107
|
-
8.8
|
HIGH
|
Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted backup data.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5133
|
cpe:2.3:o:apple:iphone_os:7.0:* cpe:2.3:o:apple:iphone_os:7.0.5:* cpe:2.3:o:apple:iphone_os:7.0.4:* cpe:2.3:o:…
|
|
7.0.6
|
|
|
2024-11-21 10:57
2014-03-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3108
|
7.4
5.8
|
HIGH
Network
|
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-1266
|
cpe:2.3:o:apple:iphone_os:*:*
|
7.0 6.0
|
|
|
7.0.6 6.1.6
|
2024-11-21 11:03
2014-02-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3109
|
4.6
4.9
|
MEDIUM
Physics
|
The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account act…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2019
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
7.1
|
2024-11-21 11:05
2014-02-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3110
|
-
7.5
|
HIGH
|
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft W…
|
CWE-415
Double Free
|
CVE-2014-1252
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
7.0
|
|
|
2024-11-21 11:03
2014-01-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|