|
3371
|
-
5.0
|
MEDIUM
|
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2011-3887
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
5.1
|
2024-11-21 10:31
2011-10-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3372
|
-
7.5
|
HIGH
|
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading…
|
CWE-416
Use After Free
|
CVE-2011-3885
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
5.1
|
2024-11-21 10:31
2011-10-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3373
|
-
4.3
|
MEDIUM
|
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (…
|
CWE-79
Cross-site Scripting
|
CVE-2011-3881
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
5.1
|
2024-11-21 10:31
2011-10-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3374
|
-
4.3
|
MEDIUM
|
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2011-2845
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
6.0
|
2024-11-21 10:29
2011-10-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3375
|
-
4.3
|
MEDIUM
|
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
|
CWE-255
Credentials Management
|
CVE-2011-3434
|
cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:…
|
|
|
|
|
2024-11-21 10:30
2011-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3376
|
-
5.0
|
MEDIUM
|
The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.
|
CWE-399
Resource Management Errors
|
CVE-2011-3432
|
cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:…
|
|
|
|
|
2024-11-21 10:30
2011-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3377
|
-
2.1
|
LOW
|
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state informati…
|
CWE-200
Information Exposure
|
CVE-2011-3431
|
cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:…
|
|
|
|
|
2024-11-21 10:30
2011-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3378
|
-
9.3
|
HIGH
|
The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to ha…
|
NVD-CWE-Other
|
CVE-2011-3430
|
cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:…
|
|
|
|
|
2024-11-21 10:30
2011-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3379
|
-
2.1
|
LOW
|
The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, which might allow physically proximate attackers to obtain sensitive information…
|
CWE-255
Credentials Management
|
CVE-2011-3429
|
cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:…
|
|
|
|
|
2024-11-21 10:30
2011-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3380
|
-
2.6
|
LOW
|
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-midd…
|
CWE-200
Information Exposure
|
CVE-2011-3427
|
cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:- cpe:2.3:o:apple:iphone_os:4.3.5:* cpe:2.3:…
|
|
|
|
|
2024-11-21 10:30
2011-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|