Apple

iPhone OS

4014 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 18.11.2013 02:55:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-time password requirement, which allows local users to complete a (1) App purchase or (2) In-App purchase by leveraging previous entry of Apple ID cre...

  • EPSS 0.06%
  • Veröffentlicht 24.10.2013 03:48:48
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by tapping the emergency-call button during a certain notification and c...

  • EPSS 0.06%
  • Veröffentlicht 24.10.2013 03:48:48
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass the passcode-failure disabled state by leveraging certain incorrect visibility of the passcode-entry view after use of the Phone app.

  • EPSS 0.05%
  • Veröffentlicht 24.10.2013 03:48:48
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.

  • EPSS 0.05%
  • Veröffentlicht 28.09.2013 03:40:55
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of taps of the emergency-call button to trigger a NUL...

  • EPSS 0.05%
  • Veröffentlicht 28.09.2013 03:40:55
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement, and open the Camera app or read the list of all recently opened apps, by leveragi...

  • EPSS 0.29%
  • Veröffentlicht 19.09.2013 10:28:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Sandbox subsystem in Apple iOS before 7 determines the sandboxing requirement for a #! application on the basis of the script interpreter instead of the script, which allows attackers to bypass intended access restrictions via a crafted applicati...

  • EPSS 0.46%
  • Veröffentlicht 19.09.2013 10:28:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite loop) via an application that writes crafted values to /dev/random.

  • EPSS 0.3%
  • Veröffentlicht 19.09.2013 10:28:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Telephony subsystem in Apple iOS before 7 does not require API conformity for access to telephony-daemon interfaces, which allows attackers to bypass intended restrictions on phone calls via a crafted app that sends direct requests to the daemon.

  • EPSS 0.29%
  • Veröffentlicht 19.09.2013 10:28:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post Tweets via a crafted app that sends direct requests to the daemon.