Apple iOS vulnerabilities
3,941 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,941
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1731LOW287
Vulnerabilities
Page 171 of 198
CVE-2014-4451HIGHCVSS 7.2≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4451 [HIGH] CWE-264 CVE-2014-4451: Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier fo
Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lock-screen protection mechanism via a series of guesses.
nvd
CVE-2014-4457HIGHCVSS 7.5≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4457 [HIGH] CWE-264 CVE-2014-4457: The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver
The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted application that is run during a time period when debugging is not enabled.
nvd
CVE-2014-4452MEDIUMCVSS 5.4≥ 8.0, < 8.1.12014-11-18
CVE-2014-4452 [MEDIUM] CWE-399 CVE-2014-4452: WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to exec
WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4462.
nvd
CVE-2014-4459MEDIUMCVSS 6.8fixed in 8.1.32014-11-18
CVE-2014-4459 [MEDIUM] CVE-2014-4459: Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attacker
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
nvd
CVE-2014-4453MEDIUMCVSS 5.0≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4453 [MEDIUM] CWE-200 CVE-2014-4453: Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotl
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-4462MEDIUMCVSS 5.8≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4462 [MEDIUM] CVE-2014-4462: WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to exec
WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4452.
nvd
CVE-2014-4463LOWCVSS 2.1≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4463 [LOW] CWE-264 CVE-2014-4463: Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection me
Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or transmit a Photo Library photo, via the FaceTime "Leave a Message" feature.
nvd
CVE-2014-4455LOWCVSS 2.1≤ 8.1.22014-11-18
CVE-2014-4455 [LOW] CWE-264 CVE-2014-4455: dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segmen
dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.
nvd
CVE-2014-4460LOWCVSS 2.1≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4460 [LOW] CWE-200 CVE-2014-4460: CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cac
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.
nvd
CVE-2014-4449MEDIUMCVSS 6.8≤ 8.0.22014-10-22
CVE-2014-4449 [MEDIUM] CWE-310 CVE-2014-4449: iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, whic
iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2014-4448LOWCVSS 1.9≤ 8.0.22014-10-22
CVE-2014-4448 [LOW] CWE-310 CVE-2014-4448: House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.
nvd
CVE-2014-4450LOWCVSS 1.9≤ 8.0.22014-10-22
CVE-2014-4450 [LOW] CWE-255 CVE-2014-4450: The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.
nvd
CVE-2014-3192HIGHCVSS 7.5≤ 8.1.22014-10-08
CVE-2014-3192 [HIGH] CWE-416 CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/Pro
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-4380CRITICALCVSS 9.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4380 [CRITICAL] CWE-119 CVE-2014-4380: The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds che
The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code in the kernel's context via a crafted application.
nvd
CVE-2014-4381CRITICALCVSS 9.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4381 [CRITICAL] CWE-119 CVE-2014-4381: Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operatio
Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.
nvd
CVE-2014-4405CRITICALCVSS 9.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4405 [CRITICAL] CVE-2014-4405: IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code i
IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.
nvd
CVE-2014-4389CRITICALCVSS 9.3PoC≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4389 [CRITICAL] CWE-189 CVE-2014-4389: Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute ar
Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted API arguments.
nvd
CVE-2014-4418HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4418 [HIGH] CVE-2014-4418: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object meta
IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4388.
nvd
CVE-2014-4422HIGHCVSS 8.1≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4422 [HIGH] CWE-310 CVE-2014-4422: The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator du
The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator during the early portion of the boot process, which allows attackers to bypass certain kernel-hardening protection mechanisms by using a user-space process to observe data related to the random numbers.
nvd
CVE-2014-4375HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4375 [HIGH] CVE-2014-4375: Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain pri
Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.
nvd