CVE-2013-3955
- EPSS 0.06%
- Veröffentlicht 05.06.2013 14:39:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have u...
CVE-2013-3948
- EPSS 0.27%
- Veröffentlicht 05.06.2013 14:39:55
- Zuletzt bearbeitet 29.04.2026 01:13:23
Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download...
- EPSS 0.81%
- Veröffentlicht 05.06.2013 14:39:55
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack-based buffer overflow in the openSharedCacheFile function in dyld.cpp in dyld in Apple iOS 5.1.x and 6.x through 6.1.3 makes it easier for attackers to conduct untethering attacks via a long string in the DYLD_SHARED_CACHE_DIR environment varia...
CVE-2013-3951
- EPSS 0.06%
- Veröffentlicht 05.06.2013 14:39:55
- Zuletzt bearbeitet 29.04.2026 01:13:23
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a prog...
CVE-2013-3953
- EPSS 0.06%
- Veröffentlicht 05.06.2013 14:39:55
- Zuletzt bearbeitet 29.04.2026 01:13:23
The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8.x does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted call...
CVE-2013-1019
- EPSS 3.63%
- Veröffentlicht 24.05.2013 16:43:58
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
CVE-2013-2842
- EPSS 21.1%
- Veröffentlicht 22.05.2013 13:29:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.
CVE-2013-1007
- EPSS 1.31%
- Veröffentlicht 20.05.2013 14:44:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability...
CVE-2013-1008
- EPSS 1.03%
- Veröffentlicht 20.05.2013 14:44:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability...
CVE-2013-1010
- EPSS 1.31%
- Veröffentlicht 20.05.2013 14:44:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability...