CVE-2013-0981
- EPSS 0.05%
- Veröffentlicht 20.03.2013 14:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.
CVE-2013-0964
- EPSS 0.06%
- Veröffentlicht 29.01.2013 05:58:54
- Zuletzt bearbeitet 29.04.2026 01:13:23
The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a ...
- EPSS 0.27%
- Veröffentlicht 11.03.2011 22:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier for remote IPv6 servers to tra...
CVE-2011-0162
- EPSS 2.29%
- Veröffentlicht 11.03.2011 22:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.
CVE-2010-2806
- EPSS 9.38%
- Veröffentlicht 19.08.2010 18:00:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings i...
CVE-2010-2807
- EPSS 5.19%
- Veröffentlicht 19.08.2010 18:00:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
CVE-2010-2808
- EPSS 7.8%
- Veröffentlicht 19.08.2010 18:00:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Typ...
CVE-2010-2805
- EPSS 5.63%
- Veröffentlicht 19.08.2010 18:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ...
CVE-2010-2249
- EPSS 1.57%
- Veröffentlicht 30.06.2010 18:30:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.