Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 164 of 197
CVE-2015-3750MEDIUMCVSS 6.4≤ 8.4fixed in 8.4.12015-08-16
CVE-2015-3750 [MEDIUM] CWE-254 CVE-2015-3750: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network
nvd
CVE-2015-3759MEDIUMCVSS 4.6≤ 8.42015-08-16
CVE-2015-3759 [MEDIUM] CWE-59 CVE-2015-3759: Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on f
Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink.
nvd
CVE-2015-3763MEDIUMCVSS 4.3≤ 8.42015-08-16
CVE-2015-3763 [MEDIUM] CWE-19 CVE-2015-3763: Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows
Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site.
nvd
CVE-2015-3755MEDIUMCVSS 4.3fixed in 8.4.12015-08-16
CVE-2015-3755 [MEDIUM] CWE-254 CVE-2015-3755: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.
nvd
CVE-2015-3745MEDIUMCVSS 6.8fixed in 8.4.12015-08-16
CVE-2015-3745 [MEDIUM] CWE-119 CVE-2015-3745: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvd
CVE-2015-3749MEDIUMCVSS 6.8fixed in 8.4.12015-08-16
CVE-2015-3749 [MEDIUM] CWE-119 CVE-2015-3749: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvd
CVE-2015-3736MEDIUMCVSS 6.8fixed in 8.4.12015-08-16
CVE-2015-3736 [MEDIUM] CWE-119 CVE-2015-3736: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvd
CVE-2015-3743MEDIUMCVSS 6.8fixed in 8.4.12015-08-16
CVE-2015-3743 [MEDIUM] CWE-119 CVE-2015-3743: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvd
CVE-2015-3758MEDIUMCVSS 4.3≤ 8.42015-08-16
CVE-2015-3758 [MEDIUM] CWE-20 CVE-2015-3758: UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation req
UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation requirement and initiate arbitrary FaceTime calls via an app that provides a crafted URL.
nvd
CVE-2015-3756LOWCVSS 2.1≤ 8.42015-08-16
CVE-2015-3756 [LOW] CWE-254 CVE-2015-3756: The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within th
The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.
nvd
CVE-2015-3778LOWCVSS 3.3≤ 8.42015-08-16
CVE-2015-3778 [LOW] CWE-200 CVE-2015-3778: bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentiall
bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentially sensitive information about MAC addresses seen in previous Wi-Fi sessions by sniffing an 802.11 network for DNAv4 broadcast traffic.
nvd
CVE-2015-1819MEDIUMCVSS 5.0≤ 9.2.12015-08-14
CVE-2015-1819 [MEDIUM] CWE-399 CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) vi
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
nvd
CVE-2015-5523MEDIUMCVSS 4.3≤ 8.22015-08-11
CVE-2015-5523 [MEDIUM] CWE-119 CVE-2015-5523: The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial o
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
nvd
CVE-2015-5522MEDIUMCVSS 6.8≤ 8.22015-08-11
CVE-2015-5522 [MEDIUM] CWE-119 CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
nvd
CVE-2015-3717HIGHCVSS 7.5fixed in 8.42015-07-03
CVE-2015-3717 [HIGH] CWE-120 CVE-2015-3717: Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and
Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2015-3710MEDIUMCVSS 4.3≤ 8.32015-07-03
CVE-2015-3710 [MEDIUM] CWE-254 CVE-2015-3710: Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh op
Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh operation, and consequently cause a visit to an arbitrary web site, via a crafted HTML e-mail message.
nvd
CVE-2015-3723MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3723 [MEDIUM] CWE-119 CVE-2015-3723: CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a de
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724.
nvd
CVE-2015-3703MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3703 [MEDIUM] CWE-119 CVE-2015-3703: ImageIO in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary
ImageIO in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image.
nvd
CVE-2015-3690MEDIUMCVSS 4.3≤ 8.32015-07-03
CVE-2015-3690 [MEDIUM] CWE-200 CVE-2015-3690: The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain
The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
nvd
CVE-2015-3719MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3719 [MEDIUM] CVE-2015-3719: TrueTypeScaler in FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers
TrueTypeScaler in FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3694.
nvd