Skip to main content

Vendor/product archive

apple / tvos CVEs

Beta · best-effort

2,082 CVEs tagged to apple / tvos150 Critical, 1,138 High, 743 Medium, 51 Low, 0 Unrated.

CVE-2014-4484

Published Jan 30, 2015

FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4483

Published Jan 30, 2015

Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial o…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4481

Published Jan 30, 2015

Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denia…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4480

Published Jan 30, 2015

Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by crea…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4465

Published Dec 10, 2014

WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4462

Published Nov 18, 2014

WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicat…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-4461

Published Nov 18, 2014

The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-4455

Published Nov 18, 2014

dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3192

Published Oct 8, 2014

Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Ch…

CVSS 7.5 · High

CVE-2014-4422

Published Sep 18, 2014

The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator during the early portion of the boot process, which allows attackers to bypass ce…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4421

Published Sep 18, 2014

The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-c…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 1,976-2,000 of 2,082 CVEsPage 80 of 84