Show filters
126 Total Results
Displaying 111-120 of 126
Sort by:
Attacker Value
Unknown
CVE-2011-3259
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remote attackers to cause a denial of service (resource consumption) by making many connection attempts.
0
Attacker Value
Unknown
CVE-2011-3253
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive information via an arbitrary certificate.
0
Attacker Value
Unknown
CVE-2011-3434
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
0
Attacker Value
Unknown
CVE-2011-3432
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.
0
Attacker Value
Unknown
CVE-2011-3243
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
0
Attacker Value
Unknown
CVE-2011-3245
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.
0
Attacker Value
Unknown
CVE-2011-3427
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2011-3426
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
0
Attacker Value
Unknown
CVE-2011-3430
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.
0
Attacker Value
Unknown
CVE-2011-3257
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a different account's cookie.
0