Apple

iPhone OS

3748 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 10.57%
  • Veröffentlicht 11.09.2008 01:13:09
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style...

  • EPSS 0.8%
  • Veröffentlicht 27.08.2008 20:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

  • EPSS 0.07%
  • Veröffentlicht 16.01.2008 02:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls.

  • EPSS 1.3%
  • Veröffentlicht 27.09.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Service Discovery Protocol (SDP) packets, related to insufficient input va...

  • EPSS 0.68%
  • Veröffentlicht 27.09.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.

  • EPSS 0.99%
  • Veröffentlicht 27.09.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.

  • EPSS 36.79%
  • Veröffentlicht 23.07.2007 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code vi...

  • EPSS 0.44%
  • Veröffentlicht 25.06.2007 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site...