Show filters
137 Total Results
Displaying 1-10 of 137
Sort by:
Attacker Value
Unknown

CVE-2023-45866

Disclosure Date: December 08, 2023 (last updated December 21, 2024)
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Attacker Value
Unknown

CVE-2019-15165

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
Attacker Value
Unknown

CVE-2019-9506

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
Attacker Value
Unknown

CVE-2013-5145

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message.
0
Attacker Value
Unknown

CVE-2013-5152

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
0
Attacker Value
Unknown

CVE-2013-5151

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.
0
Attacker Value
Unknown

CVE-2013-5139

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds array access) via a crafted application.
0
Attacker Value
Unknown

CVE-2013-5157

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post Tweets via a crafted app that sends direct requests to the daemon.
0
Attacker Value
Unknown

CVE-2013-5141

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which allows attackers to cause a denial of service (infinite loop and device hang) via a crafted application, related to an "integer truncation vulnerability."
0
Attacker Value
Unknown

CVE-2013-5147

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging a race condition involving phone calls and ejection of a SIM card.
0