Vulnerabilities > Apple > Iphone OS

DATE CVE VULNERABILITY TITLE RISK
2009-04-17 CVE-2009-0946 Integer Overflow OR Wraparound vulnerability in multiple products
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
7.5
2008-11-25 CVE-2008-4233 Unspecified vulnerability in Apple Iphone OS and Safari
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.
network
high complexity
apple
2.6
2008-11-25 CVE-2008-4232 Unspecified vulnerability in Apple Iphone OS and Safari
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
network
low complexity
apple
5.0
2008-11-25 CVE-2008-4231 Resource Management Errors vulnerability in Apple Iphone OS and Safari
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
network
apple CWE-399
critical
9.3
2008-11-25 CVE-2008-4230 Information Exposure vulnerability in Apple Iphone OS
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by reading these messages.
local
apple CWE-200
1.9
2008-11-25 CVE-2008-4229 Race Condition vulnerability in Apple Iphone OS
Race condition in the Passcode Lock feature in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.0 through 2.1 allows physically proximate attackers to remove the lock and launch arbitrary applications by restoring the device from a backup.
local
high complexity
apple CWE-362
3.7
2008-11-25 CVE-2008-4228 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows physically proximate attackers to leverage the emergency-call ability of locked devices to make a phone call to an arbitrary number.
local
low complexity
apple CWE-264
3.6
2008-11-25 CVE-2008-4227 Cryptographic Issues vulnerability in Apple Iphone OS
Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level than was previously used, which makes it easier for remote attackers to obtain sensitive information or hijack a connection by decrypting network traffic.
network
low complexity
apple CWE-310
7.5
2008-11-25 CVE-2008-1586 Resource Management Errors vulnerability in Apple Iphone OS
ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory consumption and device reset) via a crafted TIFF image.
network
apple CWE-399
7.1
2008-10-10 CVE-2008-4211 Numeric Errors vulnerability in Apple Iphone OS, mac OS X and mac OS X Server
Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
network
low complexity
apple CWE-189
critical
10.0