CVE-2014-4357
- EPSS 0.08%
- Veröffentlicht 18.09.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.
- EPSS 0.59%
- Veröffentlicht 18.09.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, which allows attackers to determine the frontmost app by leveraging access to a crafted background app.
- EPSS 0.59%
- Veröffentlicht 18.09.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app.
- EPSS 0.76%
- Veröffentlicht 18.09.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web site, (2) an https web site with an unacceptable X.509 certificate, or (3...
CVE-2014-4364
- EPSS 0.5%
- Veröffentlicht 18.09.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryp...
- EPSS 0.78%
- Veröffentlicht 18.09.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
CVE-2014-1367
- EPSS 1.58%
- Veröffentlicht 01.07.2014 10:17:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft...
CVE-2014-1368
- EPSS 1.58%
- Veröffentlicht 01.07.2014 10:17:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft...
CVE-2014-1382
- EPSS 3.32%
- Veröffentlicht 01.07.2014 10:17:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft...
CVE-2014-1348
- EPSS 0.11%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mou...