Skip to main content

Vendor/product archive

apple / iphone_os CVEs

Beta · best-effort

4,511 CVEs tagged to apple / iphone_os443 Critical, 1,816 High, 1,945 Medium, 307 Low, 0 Unrated.

CVE-2010-1753

Published Jun 22, 2010

ImageIO in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1752

Published Jun 22, 2010

Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (applica…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1751

Published Jun 22, 2010

Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not prevent photo-library access, which might allow remote attackers to obtain location information via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1407

Published Jun 22, 2010

WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1226

Published Apr 1, 2010

The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboar…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1181

Published Mar 29, 2010

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a M…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1180

Published Mar 29, 2010

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception str…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1179

Published Mar 29, 2010

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in t…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1178

Published Mar 29, 2010

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1177

Published Mar 29, 2010

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving do…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1176

Published Mar 29, 2010

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0496

Published Feb 3, 2010

FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / U…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0038

Published Feb 3, 2010

Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or mod…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3273

Published Sep 21, 2009

iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3271

Published Sep 21, 2009

Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2815

Published Sep 10, 2009

The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2797

Published Sep 10, 2009

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2796

Published Sep 10, 2009

The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-2795

Published Sep 10, 2009

Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 4,426-4,450 of 4,511 CVEsPage 178 of 181