|
3451
|
-
4.3
|
MEDIUM
|
Photos in Apple iOS before 4.2 enables support for HTTP Basic Authentication over an unencrypted connection, which allows man-in-the-middle attackers to read MobileMe account passwords by spoofing a …
|
CWE-200
Information Exposure
|
CVE-2010-3831
|
cpe:2.3:o:apple:iphone_os:4.0:* cpe:2.3:o:apple:iphone_os:4.0.2:* cpe:2.3:o:apple:iphone_os:4.0.1:* cpe:2.3:o:…
|
|
4.1
|
|
|
2024-11-21 10:19
2010-11-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3452
|
-
7.2
|
HIGH
|
Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3830
|
cpe:2.3:o:apple:iphone_os:4.0:* cpe:2.3:o:apple:iphone_os:4.0.2:* cpe:2.3:o:apple:iphone_os:4.0.1:* cpe:2.3:o:…
|
|
4.1
|
|
|
2024-11-21 10:19
2010-11-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3453
|
-
5.8
|
MEDIUM
|
WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetching property, as demonstrated by an HTML e-mail m…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3829
|
cpe:2.3:o:apple:iphone_os:4.0:* cpe:2.3:o:apple:iphone_os:4.0.2:* cpe:2.3:o:apple:iphone_os:4.0.1:* cpe:2.3:o:…
|
|
4.1
|
|
|
2024-11-21 10:19
2010-11-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3454
|
-
4.3
|
MEDIUM
|
iAd Content Display in Apple iOS before 4.2 allows man-in-the-middle attackers to make calls via a crafted URL in an ad.
|
NVD-CWE-Other
|
CVE-2010-3828
|
cpe:2.3:o:apple:iphone_os:4.0:* cpe:2.3:o:apple:iphone_os:4.0.2:* cpe:2.3:o:apple:iphone_os:4.0.1:* cpe:2.3:o:…
|
|
4.1
|
|
|
2024-11-21 10:19
2010-11-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3455
|
-
4.3
|
MEDIUM
|
Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via uns…
|
CWE-20
Improper Input Validation
|
CVE-2010-3827
|
cpe:2.3:o:apple:iphone_os:4.0:* cpe:2.3:o:apple:iphone_os:4.0.2:* cpe:2.3:o:apple:iphone_os:4.0.1:* cpe:2.3:o:…
|
|
4.1
|
|
|
2024-11-21 10:19
2010-11-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3456
|
-
4.3
|
MEDIUM
|
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4008
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.2
|
2024-11-21 10:20
2010-11-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3457
|
-
6.8
|
MEDIUM
|
Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF fi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-1817
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.1
|
2024-11-21 10:15
2010-09-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3458
|
-
6.8
|
MEDIUM
|
Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service…
|
CWE-399
Resource Management Errors
|
CVE-2010-1815
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.1
|
2024-11-21 10:15
2010-09-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3459
|
-
6.8
|
MEDIUM
|
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicat…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-1814
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.1
|
2024-11-21 10:15
2010-09-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3460
|
-
6.8
|
MEDIUM
|
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involv…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-1813
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.1
|
2024-11-21 10:15
2010-09-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|