CVE-2014-1349
- EPSS 1.54%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.
CVE-2014-1350
- EPSS 0.06%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
CVE-2014-1351
- EPSS 0.07%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.
CVE-2014-1352
- EPSS 0.07%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.
CVE-2014-1353
- EPSS 0.07%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vec...
CVE-2014-1354
- EPSS 1.31%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data...
CVE-2014-1355
- EPSS 0.06%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in IOReporting in Apple OS X before 10.9.4, allows local users to cause a denial of service (NULL pointer dereference and reboot) via crafted API argument...
- EPSS 3.06%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages.
- EPSS 3.06%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that generates log messages.
- EPSS 3.19%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.