Vulnerabilities > Apple > Iphone OS > 7.1.1

DATE CVE VULNERABILITY TITLE RISK
2014-07-01 CVE-2014-1354 Resource Management Errors vulnerability in Apple Iphone OS
CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data.
network
apple CWE-399
6.8
2014-07-01 CVE-2014-1353 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vectors.
local
low complexity
apple CWE-264
3.6
2014-07-01 CVE-2014-1352 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.
local
apple CWE-264
1.9
2014-07-01 CVE-2014-1351 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.
local
low complexity
apple CWE-264
3.6
2014-07-01 CVE-2014-1350 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
local
low complexity
apple CWE-264
4.6
2014-07-01 CVE-2014-1349 Multiple Security vulnerability in Apple iOS Prior to 7.1.2
Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.
network
apple
6.8
2014-07-01 CVE-2014-1348 Cryptographic Issues vulnerability in Apple Iphone OS
Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting the data partition.
local
low complexity
apple CWE-310
2.1
2014-07-01 CVE-2014-1345 Multiple Security vulnerability in Apple Iphone OS and Safari
WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.
network
apple
4.3
2014-07-01 CVE-2014-1325 Buffer Errors vulnerability in Apple Iphone OS, Safari and Tvos
WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.
network
apple CWE-119
6.8
2013-06-05 CVE-2013-3951 Improper Input Validation vulnerability in Apple Iphone OS, mac OS X and Watchos
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.
local
low complexity
apple CWE-20
4.6