VYPR

iOS

by Apple Inc.

CVEs (3,710)

  • CVE-2013-0957Sep 19, 2013
    risk 0.00cvss —epss 0.01

    Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Erase Data setting, by leveraging the presence of an app in the third-party sandbox.

  • CVE-2011-2391Sep 19, 2013
    risk 0.00cvss —epss 0.01

    The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets.

  • CVE-2013-4616Jun 18, 2013
    risk 0.00cvss —epss 0.01

    The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK passphrases, which makes it easier for remote attackers to obtain access via a…

  • CVE-2013-3955Jun 5, 2013
    risk 0.00cvss —epss 0.00

    The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via…

  • CVE-2013-3951Jun 5, 2013
    risk 0.00cvss —epss 0.00

    sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path…

  • CVE-2013-3950Jun 5, 2013
    risk 0.00cvss —epss 0.02

    Stack-based buffer overflow in the openSharedCacheFile function in dyld.cpp in dyld in Apple iOS 5.1.x and 6.x through 6.1.3 makes it easier for attackers to conduct untethering attacks via a long string in the DYLD_SHARED_CACHE_DIR environment variable.

  • CVE-2013-3948Jun 5, 2013
    risk 0.00cvss —epss 0.02

    Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download-manifest itms-services://…

  • CVE-2013-0981Mar 20, 2013
    risk 0.00cvss —epss 0.00

    The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.

  • CVE-2013-0980Mar 20, 2013
    risk 0.00cvss —epss 0.00

    The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging an error in the emergency-call feature.

  • CVE-2013-0979Mar 20, 2013
    risk 0.00cvss —epss 0.00

    lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the permission-setting step of a backup restoration, which allows local users to change the permissions of arbitrary files via a backup that contains a pathname with a symlink.

  • CVE-2013-0978Mar 20, 2013
    risk 0.00cvss —epss 0.00

    The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.

  • CVE-2013-0977Mar 20, 2013
    risk 0.00cvss —epss 0.00

    dyld in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not properly manage the state of file loading for Mach-O executable files, which allows local users to bypass intended code-signing requirements via a file that contains overlapping segments.

  • CVE-2013-0974Jan 29, 2013
    risk 0.00cvss —epss 0.01

    StoreKit in Apple iOS before 6.1 does not properly handle the disabling of JavaScript within the preferences configuration of Mobile Safari, which allows remote attackers to bypass intended access restrictions and execute JavaScript code via a web site with a Smart App Banner.

  • CVE-2013-0968Jan 29, 2013
    risk 0.00cvss —epss 0.01

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

  • CVE-2013-0964Jan 29, 2013
    risk 0.00cvss —epss 0.01

    The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a length of less than one page.

  • CVE-2013-0963Jan 29, 2013
    risk 0.00cvss —epss 0.00

    Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.

  • CVE-2013-0959Jan 29, 2013
    risk 0.00cvss —epss 0.02

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

  • CVE-2013-0958Jan 29, 2013
    risk 0.00cvss —epss 0.02

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

  • CVE-2013-0956Jan 29, 2013
    risk 0.00cvss —epss 0.02

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

  • CVE-2013-0955Jan 29, 2013
    risk 0.00cvss —epss 0.02

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

Page 178 of 186