Total
3262 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-1085 | 1 Apple | 1 Iphone Os | 2017-01-02 | 1.9 LOW | N/A |
AppleKeyStore in Apple iOS before 8.3 does not properly restrict a certain passcode-confirmation interface, which makes it easier for attackers to verify correct passcode guesses via a crafted app. | |||||
CVE-2015-1155 | 1 Apple | 2 Iphone Os, Safari | 2017-01-02 | 4.3 MEDIUM | N/A |
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files via a crafted web site. | |||||
CVE-2015-1116 | 1 Apple | 1 Iphone Os | 2017-01-02 | 2.1 LOW | N/A |
The UIKit View component in Apple iOS before 8.3 displays unblurred application snapshots in the Task Switcher, which makes it easier for physically proximate attackers to obtain sensitive information by reading the device screen. | |||||
CVE-2015-1113 | 1 Apple | 1 Iphone Os | 2017-01-02 | 1.9 LOW | N/A |
The Sandbox Profiles component in Apple iOS before 8.3 allows attackers to read the (1) telephone number or (2) e-mail address of a recent contact via a crafted app. | |||||
CVE-2015-1111 | 1 Apple | 1 Iphone Os | 2017-01-02 | 5.0 MEDIUM | N/A |
Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain sensitive information by reading a history file. | |||||
CVE-2015-1109 | 1 Apple | 1 Iphone Os | 2017-01-02 | 2.1 LOW | N/A |
NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file. | |||||
CVE-2015-1108 | 1 Apple | 1 Iphone Os | 2017-01-02 | 2.1 LOW | N/A |
The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses. | |||||
CVE-2015-1107 | 1 Apple | 1 Iphone Os | 2017-01-02 | 1.9 LOW | N/A |
The Lock Screen component in Apple iOS before 8.3 does not properly implement the erasure feature for incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses. | |||||
CVE-2015-1106 | 1 Apple | 1 Iphone Os | 2017-01-02 | 2.1 LOW | N/A |
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard. | |||||
CVE-2015-3726 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.6 MEDIUM | N/A |
The Telephony subsystem in Apple iOS before 8.4 allows physically proximate attackers to execute arbitrary code via a crafted (1) SIM or (2) UIM card. | |||||
CVE-2015-3725 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.3 MEDIUM | N/A |
MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app. | |||||
CVE-2015-3724 | 1 Apple | 1 Iphone Os | 2016-12-30 | 6.8 MEDIUM | N/A |
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723. | |||||
CVE-2015-3723 | 1 Apple | 1 Iphone Os | 2016-12-30 | 6.8 MEDIUM | N/A |
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724. | |||||
CVE-2015-3722 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.3 MEDIUM | N/A |
Application Store in Apple iOS before 8.4 does not ensure the uniqueness of bundle IDs, which allows attackers to cause a denial of service (ID collision and launch outage) via a crafted universal provisioning profile app. | |||||
CVE-2015-3659 | 1 Apple | 3 Iphone Os, Mac Os X, Safari | 2016-12-27 | 6.8 MEDIUM | N/A |
The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site. | |||||
CVE-2015-3728 | 1 Apple | 1 Iphone Os | 2016-12-27 | 4.8 MEDIUM | N/A |
The WiFi Connectivity feature in Apple iOS before 8.4 allows remote Wi-Fi access points to trigger an automatic association, with an arbitrary security type, by operating with a recognized ESSID within an 802.11 network's coverage area. | |||||
CVE-2015-3727 | 1 Apple | 3 Iphone Os, Mac Os X, Safari | 2016-12-27 | 6.8 MEDIUM | N/A |
WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site. | |||||
CVE-2015-3658 | 1 Apple | 3 Iphone Os, Mac Os X, Safari | 2016-12-27 | 6.8 MEDIUM | N/A |
The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site. | |||||
CVE-2015-6999 | 1 Apple | 1 Iphone Os | 2016-12-23 | 5.0 MEDIUM | N/A |
The OCSP client in Apple iOS before 9.1 does not check for certificate expiry, which allows remote attackers to spoof a valid certificate by leveraging access to a revoked certificate. | |||||
CVE-2015-7000 | 1 Apple | 1 Iphone Os | 2016-12-23 | 2.1 LOW | N/A |
Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon after a setting was disabled. |