|
3501
|
-
6.8
|
MEDIUM
|
Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allow remote attackers to execute …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2206
|
cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0.1:* cpe:2.3:o:ap…
|
|
3.0.1 3.1
|
|
|
2026-04-23 09:35
2009-09-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3502
|
-
5.8
|
MEDIUM
|
Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoo…
|
NVD-CWE-Other
|
CVE-2009-2199
|
cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0.1:* cpe:2.3:o:ap…
|
|
3.0.1 3.1
|
|
|
2026-04-23 09:35
2009-08-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3503
|
6.5
4.3
|
MEDIUM
Network
|
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) vi…
|
CWE-416
Use After Free
|
CVE-2009-2416
|
cpe:2.3:o:apple:iphone_os:*:*
|
2.0
|
|
|
4.0
|
2026-04-23 09:35
2009-08-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3504
|
-
10.0
|
HIGH
|
Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS…
|
NVD-CWE-noinfo
|
CVE-2009-2204
|
cpe:2.3:o:apple:iphone_os:2.1:* cpe:2.3:o:apple:iphone_os:2.0:* cpe:2.3:o:apple:iphone_os:2.0.2:* cpe:2.3:o:ap…
|
|
3.0
|
|
|
2026-04-23 09:35
2009-08-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3505
|
-
9.3
|
HIGH
|
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly othe…
|
CWE-189
Numeric Errors
|
CVE-2009-1725
|
cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0.1:* cpe:2.3:o:ap…
|
|
3.0.1 3.1
|
|
|
2026-04-23 09:35
2009-07-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3506
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers t…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1724
|
cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0:* cpe:2.3:o:apple:iphone_os:3.0.1:* cpe:2.3:o:ap…
|
|
3.0.1 3.1
|
|
|
2026-04-23 09:35
2009-07-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3507
|
-
7.1
|
HIGH
|
WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memor…
|
CWE-399
Resource Management Errors
|
CVE-2009-1692
|
cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2.1:* cpe:2.3:o:ap…
|
|
|
|
|
2026-04-23 09:35
2009-06-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3508
|
-
7.8
|
HIGH
|
The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted ICMP echo…
|
NVD-CWE-Other
|
CVE-2009-1683
|
cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2.1:* cpe:2.3:o:ap…
|
|
|
|
|
2026-04-23 09:35
2009-06-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3509
|
-
2.1
|
LOW
|
Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows ph…
|
CWE-200
Information Exposure
|
CVE-2009-1680
|
cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2.1:* cpe:2.3:o:ap…
|
|
|
|
|
2026-04-23 09:35
2009-06-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3510
|
-
2.1
|
LOW
|
The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange Acti…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1679
|
cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2:* cpe:2.3:o:apple:iphone_os:2.2.1:* cpe:2.3:o:ap…
|
|
|
|
|
2026-04-23 09:35
2009-06-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|