Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 154 of 197
CVE-2015-8035LOWCVSS 2.6≤ 9.2.12015-11-18
CVE-2015-8035 [LOW] CWE-399 CVE-2015-8035: The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, whic
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
nvd
CVE-2015-7995MEDIUMCVSS 5.0≤ 9.22015-11-17
CVE-2015-7995 [MEDIUM] CVE-2015-7995: The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
nvd
CVE-2015-6979CRITICALCVSS 9.3≤ 9.0.22015-10-23
CVE-2015-6979 [CRITICAL] CWE-119 CVE-2015-6979: GasGauge in Apple iOS before 9.1 allows attackers to execute arbitrary code in a privileged context
GasGauge in Apple iOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-6988CRITICALCVSS 10.0≤ 9.0.22015-10-23
CVE-2015-6988 [CRITICAL] CVE-2015-6988: The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data s
The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data structure, which allows remote attackers to execute arbitrary code via vectors involving an unknown network-connectivity requirement.
nvd
CVE-2015-6974CRITICALCVSS 9.3≤ 9.0.22015-10-23
CVE-2015-6974 [CRITICAL] CWE-119 CVE-2015-6974: IOHIDFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers
IOHIDFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-6986CRITICALCVSS 9.3≤ 9.0.22015-10-23
CVE-2015-6986 [CRITICAL] CVE-2015-6986: com.apple.driver.AppleVXD393 in the Graphics Driver subsystem in Apple iOS before 9.1 allows attacke
com.apple.driver.AppleVXD393 in the Graphics Driver subsystem in Apple iOS before 9.1 allows attackers to execute arbitrary code via a crafted app that leverages an unspecified "type confusion."
nvd
CVE-2015-6983HIGHCVSS 8.8≤ 9.0.22015-10-23
CVE-2015-6983 [HIGH] CVE-2015-6983: Double free vulnerability in Apple iOS before 9.1 and OS X before 10.11.1 allows attackers to write
Double free vulnerability in Apple iOS before 9.1 and OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that accesses AtomicBufferedFile descriptors.
nvd
CVE-2015-6994HIGHCVSS 7.1≤ 9.0.22015-10-23
CVE-2015-6994 [HIGH] CWE-399 CVE-2015-6994: The kernel in Apple iOS before 9.1 and OS X before 10.11.1 mishandles reuse of virtual memory, which
The kernel in Apple iOS before 9.1 and OS X before 10.11.1 mishandles reuse of virtual memory, which allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2015-6975HIGHCVSS 7.5≤ 9.0.22015-10-23
CVE-2015-6975 [HIGH] CWE-119 CVE-2015-6975: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack
CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.
nvd
CVE-2015-6992HIGHCVSS 7.5≤ 9.0.22015-10-23
CVE-2015-6992 [HIGH] CVE-2015-6992: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack
CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-7017.
nvd
CVE-2015-7017HIGHCVSS 7.5≤ 9.0.22015-10-23
CVE-2015-7017 [HIGH] CVE-2015-7017: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack
CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992.
nvd
CVE-2015-7004HIGHCVSS 7.1≤ 9.0.22015-10-23
CVE-2015-7004 [HIGH] CWE-20 CVE-2015-7004: The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.
The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2015-7013MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7013 [MEDIUM] CWE-119 CVE-2015-7013: WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to ex
WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.
nvd
CVE-2015-5926MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5926 [MEDIUM] CVE-2015-5926: The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 al
The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.
nvd
CVE-2015-7008MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7008 [MEDIUM] CVE-2015-7008: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-5924MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5924 [MEDIUM] CWE-119 CVE-2015-5924: The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to
The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2015-7002MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7002 [MEDIUM] CWE-119 CVE-2015-7002: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot
WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvd
CVE-2015-6997MEDIUMCVSS 4.3≤ 9.0.22015-10-23
CVE-2015-6997 [MEDIUM] CWE-254 CVE-2015-6997: The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecR
The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.
nvd
CVE-2015-6996MEDIUMCVSS 6.8PoC≤ 9.0.22015-10-23
CVE-2015-6996 [MEDIUM] CWE-119 CVE-2015-6996: IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows at
IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-7006MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7006 [MEDIUM] CWE-22 CVE-2015-7006: Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9
Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO archive.
nvd