Search Results (Refine Search)
- CPE Product Version: cpe:/o:apple:iphone_os:3.1:-:ipodtouch
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2011-3255 |
CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application. Published: October 14, 2011; 6:55:09 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2011-3253 |
CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive information via an arbitrary certificate. Published: October 14, 2011; 6:55:09 AM -0400 |
V3.x:(not available) V2.0: 2.6 LOW |
CVE-2011-3246 |
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL. Published: October 14, 2011; 6:55:09 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2011-3245 |
The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character. Published: October 14, 2011; 6:55:09 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
CVE-2011-3243 |
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows. Published: October 14, 2011; 6:55:09 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2010-1797 |
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information. Published: August 16, 2010; 2:39:40 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |