|
3471
|
-
6.8
|
MEDIUM
|
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary …
|
CWE-129
Improper Validation of Array Index
|
CVE-2010-2806
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.2
|
2024-11-21 10:17
2010-08-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3472
|
-
6.8
|
MEDIUM
|
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (applicati…
|
CWE-20
Improper Input Validation
|
CVE-2010-2805
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.2
|
2024-11-21 10:17
2010-08-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3473
|
-
9.3
|
HIGH
|
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-1797
|
cpe:2.3:o:apple:iphone_os:4.0:- cpe:2.3:o:apple:iphone_os:4.0:- cpe:2.3:o:apple:iphone_os:4.0:* cpe:2.3:o:appl…
|
|
|
|
|
2024-11-21 10:15
2010-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3474
|
-
6.9
|
MEDIUM
|
Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2973
|
cpe:2.3:o:apple:iphone_os:4.0:- cpe:2.3:o:apple:iphone_os:4.0:- cpe:2.3:o:apple:iphone_os:4.0:* cpe:2.3:o:appl…
|
|
|
|
|
2024-11-21 10:17
2010-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3475
|
6.5
4.3
|
MEDIUM
Network
|
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing m…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2010-2249
|
cpe:2.3:o:apple:iphone_os:*:*
|
2.0
|
4.1
|
|
|
2024-11-21 10:16
2010-07-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3476
|
9.8
7.5
|
CRITICAL
Network
|
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers…
|
CWE-120
Classic Buffer Overflow
|
CVE-2010-1205
|
cpe:2.3:o:apple:iphone_os:*:*
|
2.0
|
4.1
|
|
|
2024-11-21 10:13
2010-07-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3477
|
-
1.9
|
LOW
|
Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a comp…
|
CWE-362
Race Condition
|
CVE-2010-1775
|
cpe:2.3:o:apple:iphone_os:3.1.3:* cpe:2.3:o:apple:iphone_os:3.1.2:* cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:…
|
|
3.2
|
|
|
2024-11-21 10:15
2010-06-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3478
|
-
6.4
|
MEDIUM
|
WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1757
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.0
|
2024-11-21 10:15
2010-06-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3479
|
-
5.8
|
MEDIUM
|
The Settings application in Apple iOS before 4 on the iPhone and iPod touch does not properly report the wireless network that is in use, which might make it easier for remote attackers to trick user…
|
NVD-CWE-Other
|
CVE-2010-1756
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.0
|
2024-11-21 10:15
2010-06-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3480
|
-
4.3
|
MEDIUM
|
Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the Accept Cookies preference, which makes it easier for remote web servers to track users via a cookie.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1755
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
4.0
|
2024-11-21 10:15
2010-06-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|