Vulnerabilities > Apple > Iphone OS

DATE CVE VULNERABILITY TITLE RISK
2008-11-25 CVE-2008-4228 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows physically proximate attackers to leverage the emergency-call ability of locked devices to make a phone call to an arbitrary number.
local
low complexity
apple CWE-264
3.6
2008-11-25 CVE-2008-4227 Cryptographic Issues vulnerability in Apple Iphone OS
Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level than was previously used, which makes it easier for remote attackers to obtain sensitive information or hijack a connection by decrypting network traffic.
network
low complexity
apple CWE-310
7.5
2008-11-25 CVE-2008-1586 Resource Management Errors vulnerability in Apple Iphone OS
ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory consumption and device reset) via a crafted TIFF image.
network
apple CWE-399
7.1
2008-10-10 CVE-2008-4211 Numeric Errors vulnerability in Apple Iphone OS, mac OS X and mac OS X Server
Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
network
low complexity
apple CWE-189
critical
10.0
2008-09-11 CVE-2008-3632 Resource Management Errors vulnerability in Apple Iphone, Iphone OS and Ipod Touch
Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.
network
apple CWE-399
critical
9.3
2008-09-11 CVE-2008-3612 Use of Insufficiently Random Values vulnerability in Apple Iphone OS 2.0.0/2.0.1/2.0.2
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
network
low complexity
apple CWE-330
critical
9.8
2008-08-27 CVE-2008-3281 XML Entity Expansion vulnerability in multiple products
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
6.5
2008-01-16 CVE-2008-0034 Unspecified vulnerability in Apple Iphone and Iphone OS
Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls.
local
low complexity
apple
4.6
2007-09-27 CVE-2007-3755 Improper Input Validation vulnerability in Apple Iphone and Iphone OS
Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.
network
apple CWE-20
4.3
2007-09-27 CVE-2007-3754 Improper Authentication vulnerability in Apple Iphone and Iphone OS
Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.
network
apple CWE-287
4.3