Apple

iPhone OS

3839 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 6.66%
  • Veröffentlicht 20.05.2016 10:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

  • EPSS 0.26%
  • Veröffentlicht 20.05.2016 10:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive information via a crafted app.

  • EPSS 7.72%
  • Veröffentlicht 20.05.2016 10:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecified vectors.

  • EPSS 0.24%
  • Veröffentlicht 20.05.2016 10:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

  • EPSS 0.06%
  • Veröffentlicht 29.03.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app.

  • EPSS 0.59%
  • Veröffentlicht 24.03.2016 01:59:55
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages.

  • EPSS 0.44%
  • Veröffentlicht 24.03.2016 01:59:53
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and o...

  • EPSS 0.43%
  • Veröffentlicht 24.03.2016 01:59:52
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a ...

  • EPSS 0.94%
  • Veröffentlicht 24.03.2016 01:59:51
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) via a crafted web site.

  • EPSS 2.19%
  • Veröffentlicht 24.03.2016 01:59:50
  • Zuletzt bearbeitet 12.04.2025 10:46:40

WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.