CVE-2012-3740
- EPSS 0.05%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Passcode Lock implementation in Apple iOS before 6 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
CVE-2012-3741
- EPSS 0.05%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that ...
- EPSS 0.38%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which allows remote attackers to spoof https connections by placing this character in the TITLE element of...
- EPSS 0.42%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sensitive information via a crafted app that reads log files.
- EPSS 0.41%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Telephony in Apple iOS before 6 uses an SMS message's return address as the displayed sender address, which allows remote attackers to spoof text communication via a message in which the return address does not match the originating address.
- EPSS 0.58%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Off-by-one error in Telephony in Apple iOS before 6 allows remote attackers to cause a denial of service (buffer overflow and connectivity outage) via a crafted user-data header in an SMS message.
CVE-2012-3746
- EPSS 0.34%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which allows context-dependent attackers to obtain cleartext file content by leveraging direct access to a device's filesystem.
CVE-2012-3747
- EPSS 1.8%
- Veröffentlicht 20.09.2012 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
WebKit, as used in Apple iOS before 6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
CVE-2012-3722
- EPSS 2.12%
- Veröffentlicht 20.09.2012 21:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a...
- EPSS 0.35%
- Veröffentlicht 20.09.2012 21:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed ...