Skip to main content

Vendor/product archive

apple / iphone CVEs

Beta · best-effort

23 CVEs tagged to apple / iphone3 Critical, 2 High, 16 Medium, 2 Low, 0 Unrated.

CVE-2010-1226

Published Apr 1, 2010

The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboar…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4593

Published Oct 17, 2008

Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by p…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3632

Published Sep 11, 2008

Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-3876

Published Sep 2, 2008

Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0034

Published Jan 16, 2008

Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors re…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3759

Published Sep 27, 2007

Safari in Apple iPhone 1.1.1, when requested to disable Javascript, does not disable it until Safari is restarted, which might leave Safari open to attacks that the user does not…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3761

Published Sep 27, 2007

Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1 allows remote attackers to inject arbitrary web script or HTML by causing Javascript events to be applied…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3753

Published Sep 27, 2007

Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Ser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3754

Published Sep 27, 2007

Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3755

Published Sep 27, 2007

Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3757

Published Sep 27, 2007

Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into making calls to arbitrary telephone numbers via a crafted "tel:" link that causes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3742

Published Aug 3, 2007

WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1