- EPSS 0.78%
- Veröffentlicht 18.09.2014 10:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
CVE-2014-1367
- EPSS 1.58%
- Veröffentlicht 01.07.2014 10:17:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft...
CVE-2014-1368
- EPSS 1.58%
- Veröffentlicht 01.07.2014 10:17:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft...
CVE-2014-1382
- EPSS 3.32%
- Veröffentlicht 01.07.2014 10:17:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craft...
CVE-2014-1348
- EPSS 0.11%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mou...
CVE-2014-1349
- EPSS 1.54%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.
CVE-2014-1350
- EPSS 0.06%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
CVE-2014-1351
- EPSS 0.07%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.
CVE-2014-1352
- EPSS 0.07%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.
CVE-2014-1353
- EPSS 0.07%
- Veröffentlicht 01.07.2014 10:17:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vec...