Show filters
154 Total Results
Displaying 1-10 of 154
Sort by:
Attacker Value
Unknown

CVE-2013-5145

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message.
0
Attacker Value
Unknown

CVE-2013-5152

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
0
Attacker Value
Unknown

CVE-2013-5151

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.
0
Attacker Value
Unknown

CVE-2013-5139

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds array access) via a crafted application.
0
Attacker Value
Unknown

CVE-2013-5157

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post Tweets via a crafted app that sends direct requests to the daemon.
0
Attacker Value
Unknown

CVE-2013-5141

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which allows attackers to cause a denial of service (infinite loop and device hang) via a crafted application, related to an "integer truncation vulnerability."
0
Attacker Value
Unknown

CVE-2013-5147

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging a race condition involving phone calls and ejection of a SIM card.
0
Attacker Value
Unknown

CVE-2013-5159

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
WebKit in Apple iOS before 7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive information about use of the window.webkitRequestAnimationFrame API via an IFRAME element.
0
Attacker Value
Unknown

CVE-2013-5138

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
IOCatalogue in IOKitUser in Apple iOS before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted application.
0
Attacker Value
Unknown

CVE-2013-5153

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Springboard in Apple iOS before 7 does not properly manage the lock state in Lost Mode, which allows physically proximate attackers to read notifications via unspecified vectors.
0