Apple iOS vulnerabilities

3,941 known vulnerabilities affecting apple/iphone_os.

Total CVEs
3,941
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1731LOW287

Vulnerabilities

Page 175 of 198
CVE-2014-1351LOWCVSS 3.6≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1351 [LOW] CWE-264 CVE-2014-1351: Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-scre Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.
nvd
CVE-2014-1348LOWCVSS 2.1≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1348 [LOW] CWE-310 CVE-2014-1348: Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but st Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting the data partition.
nvd
CVE-2014-1296MEDIUMCVSS 4.3≤ 7.1v7.0+6 more2014-04-23
CVE-2014-1296 [MEDIUM] CWE-264 CVE-2014-1296: CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not e CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated b
nvd
CVE-2014-1320MEDIUMCVSS 4.9≤ 7.1v7.0+6 more2014-04-23
CVE-2014-1320 [MEDIUM] CWE-200 CVE-2014-1320: IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.
nvd
CVE-2014-1295MEDIUMCVSS 6.8≤ 7.1v7.0+6 more2014-04-23
CVE-2014-1295 [MEDIUM] CWE-287 CVE-2014-1295: Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple T Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake
nvd
CVE-2014-1287HIGHCVSS 7.2PoC≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1287 [HIGH] CWE-119 CVE-2014-1287: USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to ex USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.
nvd
CVE-2013-5133HIGHCVSS 8.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2013-5133 [HIGH] CWE-264 CVE-2013-5133: Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted backup data.
nvd
CVE-2014-1271HIGHCVSS 7.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1271 [HIGH] CWE-20 CVE-2014-1271: CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API cal CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of service (assertion failure and device crash) via a crafted app.
nvd
CVE-2014-1280HIGHCVSS 7.1≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1280 [HIGH] CVE-2014-1280: Video Driver in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to cause a deni Video Driver in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to cause a denial of service (NULL pointer dereference and device hang) via a crafted video file with MPEG-4 encoding.
nvd
CVE-2014-1278HIGHCVSS 7.2≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1278 [HIGH] CWE-119 CVE-2014-1278: The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access and device crash) via a crafted call.
nvd
CVE-2014-1272MEDIUMCVSS 6.3≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1272 [MEDIUM] CWE-59 CVE-2014-1272: CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local us CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink.
nvd
CVE-2014-1292MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1292 [MEDIUM] CVE-2014-1292: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1276MEDIUMCVSS 5.0≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1276 [MEDIUM] CWE-264 CVE-2014-1276: IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks a IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that accesses an IOKit framework interface.
nvd
CVE-2014-1290MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1290 [MEDIUM] CVE-2014-1290: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2013-6835MEDIUMCVSS 5.0PoC≤ 7.0.6v7.0+5 more2014-03-14
CVE-2013-6835 [MEDIUM] CWE-264 CVE-2013-6835: TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirma TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL.
nvd
CVE-2014-1285MEDIUMCVSS 5.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1285 [MEDIUM] CWE-264 CVE-2014-1285: Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.
nvd
CVE-2014-1291MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1291 [MEDIUM] CVE-2014-1291: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
nvd
CVE-2014-1286MEDIUMCVSS 5.0≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1286 [MEDIUM] CVE-2014-1286: SpringBoard Lock Screen in Apple iOS before 7.1 allows remote attackers to cause a denial of service SpringBoard Lock Screen in Apple iOS before 7.1 allows remote attackers to cause a denial of service (lock-screen hang) by leveraging a state-management error.
nvd
CVE-2014-1273MEDIUMCVSS 5.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1273 [MEDIUM] CWE-20 CVE-2014-1273: dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing require dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing requirements by leveraging use of text-relocation instructions in a dynamic library.
nvd
CVE-2014-1294MEDIUMCVSS 6.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1294 [MEDIUM] CVE-2014-1294: WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293.
nvd