Skip to main content

Vendor/product archive

apple / iphone_os CVEs

Beta · best-effort

4,511 CVEs tagged to apple / iphone_os443 Critical, 1,816 High, 1,945 Medium, 307 Low, 0 Unrated.

CVE-2011-3257

Published Oct 14, 2011

The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intend…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3256

Published Oct 14, 2011

FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary cod…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3255

Published Oct 14, 2011

CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted applica…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3254

Published Oct 14, 2011

Cross-site scripting (XSS) vulnerability in Calendar in Apple iOS before 5 allows remote attackers to inject arbitrary web script or HTML via an invitation note.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3253

Published Oct 14, 2011

CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive informa…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3245

Published Oct 14, 2011

The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attacker…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3243

Published Oct 14, 2011

Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0228

Published Aug 29, 2011

The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2821

Published Aug 29, 2011

Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 4,326-4,350 of 4,511 CVEsPage 174 of 181