Show filters
148 Total Results
Displaying 111-120 of 148
Sort by:
Attacker Value
Unknown

CVE-2011-3434

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
0
Attacker Value
Unknown

CVE-2011-3432

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.
0
Attacker Value
Unknown

CVE-2011-3243

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
0
Attacker Value
Unknown

CVE-2011-3245

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.
0
Attacker Value
Unknown

CVE-2011-3427

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2011-3426

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
0
Attacker Value
Unknown

CVE-2011-3430

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.
0
Attacker Value
Unknown

CVE-2011-3257

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a different account's cookie.
0
Attacker Value
Unknown

CVE-2011-3260

Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word document.
0
Attacker Value
Unknown

CVE-2011-0228

Disclosure Date: August 29, 2011 (last updated October 04, 2023)
The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.
0