Apple

tvOS

1890 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 20.03.2013 14:55:04
  • Last modified 11.04.2025 00:51:21

The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted c...

  • EPSS 0.05%
  • Published 20.03.2013 14:55:04
  • Last modified 11.04.2025 00:51:21

The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.

  • EPSS 0.06%
  • Published 29.01.2013 05:58:54
  • Last modified 11.04.2025 00:51:21

The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a ...

  • EPSS 0.39%
  • Published 11.03.2011 22:55:05
  • Last modified 11.04.2025 00:51:21

The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier for remote IPv6 servers to tra...

  • EPSS 1.98%
  • Published 11.03.2011 22:55:03
  • Last modified 11.04.2025 00:51:21

Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.

Exploit
  • EPSS 9.38%
  • Published 19.08.2010 18:00:05
  • Last modified 11.04.2025 00:51:21

Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings i...

  • EPSS 5.19%
  • Published 19.08.2010 18:00:05
  • Last modified 11.04.2025 00:51:21

FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

  • EPSS 7.8%
  • Published 19.08.2010 18:00:05
  • Last modified 11.04.2025 00:51:21

Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Typ...

Exploit
  • EPSS 5.63%
  • Published 19.08.2010 18:00:04
  • Last modified 11.04.2025 00:51:21

The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ...

  • EPSS 1.57%
  • Published 30.06.2010 18:30:01
  • Last modified 11.04.2025 00:51:21

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.