|
3211
|
-
5.0
|
MEDIUM
|
The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the AS…
|
CWE-200
Information Exposure
|
CVE-2012-3749
|
cpe:2.3:o:apple:iphone_os:5.1.1:* cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:…
|
|
6.0
|
|
|
2024-11-21 10:41
2012-11-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3212
|
-
5.1
|
MEDIUM
|
Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving Jav…
|
CWE-362
Race Condition
|
CVE-2012-3748
|
cpe:2.3:o:apple:iphone_os:5.1.1:* cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:…
|
|
6.0
|
|
|
2024-11-21 10:41
2012-11-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3213
|
-
10.0
|
HIGH
|
Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-399
Resource Management Errors
|
CVE-2012-5112
|
cpe:2.3:o:apple:iphone_os:6.0:*
|
|
|
|
|
2024-11-21 10:44
2012-10-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3214
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."
|
CWE-79
Cross-site Scripting
|
CVE-2012-2889
|
cpe:2.3:o:apple:iphone_os:6.0:* cpe:2.3:o:apple:iphone_os:6.0.1:* cpe:2.3:o:apple:iphone_os:*:*
|
|
6.0.2
|
|
|
2024-11-21 10:39
2012-09-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3215
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
|
CWE-119 CWE-399
Incorrect Access of Indexable Resource ('Range Error') Resource Management Errors
|
CVE-2012-3747
|
cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:o:…
|
|
5.1.1
|
|
|
2024-11-21 10:41
2012-09-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3216
|
-
4.3
|
MEDIUM
|
UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which allows context-dependent attackers to obtain cleartext file content by leveraging direct access to a …
|
CWE-310
Cryptographic Issues
|
CVE-2012-3746
|
cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:o:…
|
|
5.1.1
|
|
|
2024-11-21 10:41
2012-09-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3217
|
-
5.0
|
MEDIUM
|
Off-by-one error in Telephony in Apple iOS before 6 allows remote attackers to cause a denial of service (buffer overflow and connectivity outage) via a crafted user-data header in an SMS message.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-3745
|
cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:o:…
|
|
5.1.1
|
|
|
2024-11-21 10:41
2012-09-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3218
|
-
5.0
|
MEDIUM
|
Telephony in Apple iOS before 6 uses an SMS message's return address as the displayed sender address, which allows remote attackers to spoof text communication via a message in which the return addre…
|
NVD-CWE-Other
|
CVE-2012-3744
|
cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:o:…
|
|
5.1.1
|
|
|
2024-11-21 10:41
2012-09-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3219
|
-
5.0
|
MEDIUM
|
The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sensitive information via a crafted app that reads lo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3743
|
cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:o:…
|
|
5.1.1
|
|
|
2024-11-21 10:41
2012-09-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3220
|
-
5.0
|
MEDIUM
|
Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which allows remote attackers to spoof https connection…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3742
|
cpe:2.3:o:apple:iphone_os:5.0:* cpe:2.3:o:apple:iphone_os:5.0.1:* cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:o:…
|
|
5.1.1
|
|
|
2024-11-21 10:41
2012-09-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|