Apple iOS vulnerabilities

3,941 known vulnerabilities affecting apple/iphone_os.

Total CVEs
3,941
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1731LOW287

Vulnerabilities

Page 171 of 198
CVE-2014-4451HIGHCVSS 7.2≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4451 [HIGH] CWE-264 CVE-2014-4451: Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier fo Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lock-screen protection mechanism via a series of guesses.
nvd
CVE-2014-4457HIGHCVSS 7.5≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4457 [HIGH] CWE-264 CVE-2014-4457: The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted application that is run during a time period when debugging is not enabled.
nvd
CVE-2014-4452MEDIUMCVSS 5.4≥ 8.0, < 8.1.12014-11-18
CVE-2014-4452 [MEDIUM] CWE-399 CVE-2014-4452: WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to exec WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4462.
nvd
CVE-2014-4459MEDIUMCVSS 6.8fixed in 8.1.32014-11-18
CVE-2014-4459 [MEDIUM] CVE-2014-4459: Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attacker Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
nvd
CVE-2014-4453MEDIUMCVSS 5.0≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4453 [MEDIUM] CWE-200 CVE-2014-4453: Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotl Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-4462MEDIUMCVSS 5.8≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4462 [MEDIUM] CVE-2014-4462: WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to exec WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4452.
nvd
CVE-2014-4463LOWCVSS 2.1≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4463 [LOW] CWE-264 CVE-2014-4463: Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection me Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or transmit a Photo Library photo, via the FaceTime "Leave a Message" feature.
nvd
CVE-2014-4455LOWCVSS 2.1≤ 8.1.22014-11-18
CVE-2014-4455 [LOW] CWE-264 CVE-2014-4455: dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segmen dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.
nvd
CVE-2014-4460LOWCVSS 2.1≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4460 [LOW] CWE-200 CVE-2014-4460: CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cac CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.
nvd
CVE-2014-4449MEDIUMCVSS 6.8≤ 8.0.22014-10-22
CVE-2014-4449 [MEDIUM] CWE-310 CVE-2014-4449: iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, whic iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2014-4448LOWCVSS 1.9≤ 8.0.22014-10-22
CVE-2014-4448 [LOW] CWE-310 CVE-2014-4448: House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.
nvd
CVE-2014-4450LOWCVSS 1.9≤ 8.0.22014-10-22
CVE-2014-4450 [LOW] CWE-255 CVE-2014-4450: The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.
nvd
CVE-2014-3192HIGHCVSS 7.5≤ 8.1.22014-10-08
CVE-2014-3192 [HIGH] CWE-416 CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/Pro Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-4380CRITICALCVSS 9.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4380 [CRITICAL] CWE-119 CVE-2014-4380: The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds che The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code in the kernel's context via a crafted application.
nvd
CVE-2014-4381CRITICALCVSS 9.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4381 [CRITICAL] CWE-119 CVE-2014-4381: Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operatio Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.
nvd
CVE-2014-4405CRITICALCVSS 9.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4405 [CRITICAL] CVE-2014-4405: IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code i IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.
nvd
CVE-2014-4389CRITICALCVSS 9.3PoC≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4389 [CRITICAL] CWE-189 CVE-2014-4389: Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute ar Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted API arguments.
nvd
CVE-2014-4418HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4418 [HIGH] CVE-2014-4418: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object meta IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4388.
nvd
CVE-2014-4422HIGHCVSS 8.1≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4422 [HIGH] CWE-310 CVE-2014-4422: The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator du The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator during the early portion of the boot process, which allows attackers to bypass certain kernel-hardening protection mechanisms by using a user-space process to observe data related to the random numbers.
nvd
CVE-2014-4375HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4375 [HIGH] CVE-2014-4375: Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain pri Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.
nvd