Show filters
148 Total Results
Displaying 121-130 of 148
Sort by:
Attacker Value
Unknown

CVE-2010-3828

Disclosure Date: November 26, 2010 (last updated October 04, 2023)
iAd Content Display in Apple iOS before 4.2 allows man-in-the-middle attackers to make calls via a crafted URL in an ad.
0
Attacker Value
Unknown

CVE-2010-1810

Disclosure Date: September 09, 2010 (last updated October 04, 2023)
FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.
0
Attacker Value
Unknown

CVE-2010-1797

Disclosure Date: August 16, 2010 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-1407

Disclosure Date: June 22, 2010 (last updated October 04, 2023)
WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.
0
Attacker Value
Unknown

CVE-2010-1775

Disclosure Date: June 22, 2010 (last updated October 04, 2023)
Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving the initial boot.
0
Attacker Value
Unknown

CVE-2010-1387

Disclosure Date: June 18, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
0
Attacker Value
Unknown

CVE-2010-1119

Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.
0
Attacker Value
Unknown

CVE-2010-0038

Disclosure Date: February 03, 2010 (last updated October 04, 2023)
Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.
0
Attacker Value
Unknown

CVE-2009-3273

Disclosure Date: September 21, 2009 (last updated October 04, 2023)
iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.
0
Attacker Value
Unknown

CVE-2009-2794

Disclosure Date: September 10, 2009 (last updated October 04, 2023)
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.
0