Vulnerabilities > Apple > Iphone OS > 6.1.2

DATE CVE VULNERABILITY TITLE RISK
2013-09-19 CVE-2013-0957 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Erase Data setting, by leveraging the presence of an app in the third-party sandbox.
network
apple CWE-264
5.8
2013-09-19 CVE-2011-2391 Improper Input Validation vulnerability in Apple Iphone OS, Itunes and mac OS X
The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets.
low complexity
apple CWE-20
6.1
2013-09-16 CVE-2013-1028 Improper Input Validation vulnerability in Apple Iphone OS and mac OS X
The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.
network
apple CWE-20
5.8
2013-09-16 CVE-2013-1026 Buffer Errors vulnerability in Apple Iphone OS and mac OS X
Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.
network
apple CWE-119
6.8
2013-09-16 CVE-2013-1025 Buffer Errors vulnerability in Apple Iphone OS and mac OS X
Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document.
network
apple CWE-119
6.8
2013-06-05 CVE-2013-3955 Improper Input Validation vulnerability in Apple products
The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem.
local
high complexity
apple CWE-20
6.2
2013-06-05 CVE-2013-3954 Improper Input Validation vulnerability in Apple Iphone OS and mac OS X
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size value in conjunction with a crafted buffer.
local
apple CWE-20
6.9
2013-06-05 CVE-2013-3953 Information Exposure vulnerability in Apple Iphone OS and mac OS X
The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8.x does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted call.
local
low complexity
apple CWE-200
4.9
2013-06-05 CVE-2013-3951 Improper Input Validation vulnerability in Apple Iphone OS, mac OS X and Watchos
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.
local
low complexity
apple CWE-20
4.6
2013-06-05 CVE-2013-3950 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
Stack-based buffer overflow in the openSharedCacheFile function in dyld.cpp in dyld in Apple iOS 5.1.x and 6.x through 6.1.3 makes it easier for attackers to conduct untethering attacks via a long string in the DYLD_SHARED_CACHE_DIR environment variable.
network
low complexity
apple CWE-119
5.0