Apple

iPhone OS

3839 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 12.03.2015 10:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.

  • EPSS 0.07%
  • Veröffentlicht 12.03.2015 10:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended activation requirement and read the home screen by leveraging an application crash during the activation process.

  • EPSS 0.69%
  • Veröffentlicht 12.03.2015 10:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CoreTelephony in Apple iOS before 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a Class 0 SMS message.

  • EPSS 0.34%
  • Veröffentlicht 12.03.2015 10:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app.

  • EPSS 5.41%
  • Veröffentlicht 12.03.2015 10:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.

Exploit
  • EPSS 4.8%
  • Veröffentlicht 11.03.2015 01:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via c...

  • EPSS 0.33%
  • Veröffentlicht 30.01.2015 11:59:49
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirection of an SSL URL to the iTunes Store.

  • EPSS 0.66%
  • Veröffentlicht 30.01.2015 11:59:25
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mach_port_kobject interface in the kernel in Apple iOS before 8.1.3 and Apple TV before 7.0.3 does not properly restrict kernel-address and heap-permutation information, which makes it easier for attackers to bypass the ASLR protection mechanism ...

  • EPSS 0.83%
  • Veröffentlicht 30.01.2015 11:59:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restric...

  • EPSS 0.21%
  • Veröffentlicht 30.01.2015 11:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, which allows attackers to bypass intended first-launch restrictions by leveraging access to an enterp...