Apple iOS vulnerabilities

3,941 known vulnerabilities affecting apple/iphone_os.

Total CVEs
3,941
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1731LOW287

Vulnerabilities

Page 177 of 198
CVE-2013-5164LOWCVSS 3.3≤ 7.0.2v7.0+1 more2013-10-24
CVE-2013-5164 [LOW] CWE-362 CVE-2013-5164: Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attac Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.
nvd
CVE-2013-5161MEDIUMCVSS 4.4≤ 7.0.1v7.02013-09-28
CVE-2013-5161 [MEDIUM] CWE-264 CVE-2013-5161: Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physic Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement, and open the Camera app or read the list of all recently opened apps, by leveraging unspecified transition errors.
nvd
CVE-2013-5160LOWCVSS 3.3≤ 7.0.1v7.02013-09-28
CVE-2013-5160 [LOW] CWE-264 CVE-2013-5160: Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to b Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of taps of the emergency-call button to trigger a NULL pointer dereference.
nvd
CVE-2013-5139CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5139 [CRITICAL] CWE-119 CVE-2013-5139: The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds array access) via a crafted application.
nvd
CVE-2013-5155HIGHCVSS 7.1≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5155 [HIGH] CWE-20 CVE-2013-5155: The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite loop) via an application that writes crafted values to /dev/random.
nvd
CVE-2013-5140HIGHCVSS 7.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5140 [HIGH] CWE-20 CVE-2013-5140: The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion fai The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion failure and device restart) via an invalid packet fragment.
nvd
CVE-2013-5141HIGHCVSS 7.1≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5141 [HIGH] CWE-189 CVE-2013-5141: The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which a The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which allows attackers to cause a denial of service (infinite loop and device hang) via a crafted application, related to an "integer truncation vulnerability."
nvd
CVE-2013-5129MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5129 [MEDIUM] CWE-79 CVE-2013-5129: Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assis Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
nvd
CVE-2013-1041MEDIUMCVSS 6.8v1.0.0v1.0.1+48 more2013-09-19
CVE-2013-1041 [MEDIUM] CWE-119 CVE-2013-1041: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-5131MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5131 [MEDIUM] CWE-79 CVE-2013-5131: Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 7 allows remote attackers to Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-5128MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5128 [MEDIUM] CWE-119 CVE-2013-5128: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1047MEDIUMCVSS 6.8v1.0.0v1.0.1+47 more2013-09-19
CVE-2013-1047 [MEDIUM] CWE-119 CVE-2013-1047: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-5152MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5152 [MEDIUM] CWE-20 CVE-2013-5152: Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web s Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
nvd
CVE-2013-5142MEDIUMCVSS 4.9≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5142 [MEDIUM] CWE-200 CVE-2013-5142: The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allow The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obtain sensitive information from kernel stack memory via the (1) msgctl API or (2) segctl API.
nvd
CVE-2013-5159MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5159 [MEDIUM] CWE-264 CVE-2013-5159: WebKit in Apple iOS before 7 allows remote attackers to bypass the Same Origin Policy and obtain pot WebKit in Apple iOS before 7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive information about use of the window.webkitRequestAnimationFrame API via an IFRAME element.
nvd
CVE-2013-1043MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-1043 [MEDIUM] CWE-119 CVE-2013-1043: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-5151MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5151 [MEDIUM] CWE-79 CVE-2013-5151: Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.
nvd
CVE-2013-5127MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5127 [MEDIUM] CWE-119 CVE-2013-5127: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-5154MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5154 [MEDIUM] CWE-264 CVE-2013-5154: The Sandbox subsystem in Apple iOS before 7 determines the sandboxing requirement for a #! applicati The Sandbox subsystem in Apple iOS before 7 determines the sandboxing requirement for a #! application on the basis of the script interpreter instead of the script, which allows attackers to bypass intended access restrictions via a crafted application.
nvd
CVE-2013-1039MEDIUMCVSS 6.8v1.0.0v1.0.1+48 more2013-09-19
CVE-2013-1039 [MEDIUM] CWE-119 CVE-2013-1039: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd