Apple iOS vulnerabilities
3,941 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,941
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1731LOW287
Vulnerabilities
Page 174 of 198
CVE-2014-1356CRITICALCVSS 10.0≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1356 [CRITICAL] CWE-119 CVE-2014-1356: Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple
Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages.
nvd
CVE-2014-1359CRITICALCVSS 10.0≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1359 [CRITICAL] CWE-189 CVE-2014-1359: Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV befor
Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.
nvd
CVE-2014-1382MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1382 [MEDIUM] CWE-119 CVE-2014-1382: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1368MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1368 [MEDIUM] CWE-119 CVE-2014-1368: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1355MEDIUMCVSS 4.9≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1355 [MEDIUM] CVE-2014-1355: The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in I
The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in IOReporting in Apple OS X before 10.9.4, allows local users to cause a denial of service (NULL pointer dereference and reboot) via crafted API arguments.
nvd
CVE-2014-1349MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1349 [MEDIUM] CVE-2014-1349: Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute
Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.
nvd
CVE-2014-1363MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1363 [MEDIUM] CWE-119 CVE-2014-1363: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1367MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1367 [MEDIUM] CWE-119 CVE-2014-1367: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1365MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1365 [MEDIUM] CWE-119 CVE-2014-1365: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1362MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1362 [MEDIUM] CWE-119 CVE-2014-1362: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1364MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1364 [MEDIUM] CWE-119 CVE-2014-1364: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1325MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1325 [MEDIUM] CWE-119 CVE-2014-1325: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1354MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1354 [MEDIUM] CWE-399 CVE-2014-1354: CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for pro
CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data.
nvd
CVE-2014-1361MEDIUMCVSS 5.0≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1361 [MEDIUM] CWE-200 CVE-2014-1361: Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does
Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.
nvd
CVE-2014-1350MEDIUMCVSS 4.6≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1350 [MEDIUM] CWE-264 CVE-2014-1350: Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iClou
Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
nvd
CVE-2014-1345MEDIUMCVSS 4.3≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1345 [MEDIUM] CVE-2014-1345: WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properl
WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2014-1366MEDIUMCVSS 6.8≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1366 [MEDIUM] CWE-119 CVE-2014-1366: WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA
nvd
CVE-2014-1352LOWCVSS 1.9≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1352 [LOW] CWE-264 CVE-2014-1352: Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempt
Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.
nvd
CVE-2014-1360LOWCVSS 2.1≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1360 [LOW] CWE-20 CVE-2014-1360: Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which make
Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors.
nvd
CVE-2014-1353LOWCVSS 3.6≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1353 [LOW] CWE-264 CVE-2014-1353: Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode,
Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vectors.
nvd