Vulnerabilities > Apple > Iphone OS > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-23 CVE-2017-7080 Improper Certificate Validation vulnerability in Apple products
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-295
5.0
2017-10-23 CVE-2017-7078 Cleartext Transmission of Sensitive Information vulnerability in Apple Iphone OS and mac OS X
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-319
5.0
2017-10-23 CVE-2017-7072 Improper Input Validation vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
apple CWE-20
4.3
2017-10-20 CVE-2017-13127 Information Exposure vulnerability in VIP
The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogue access point and a man-in-the-middle attack.
6.8
2017-10-04 CVE-2017-11122 Information Exposure vulnerability in multiple products
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.
network
low complexity
broadcom apple CWE-200
5.0
2017-09-26 CVE-2015-0874 Improper Certificate Validation vulnerability in OKB Smart Passbook 1.0.0
Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information from encrypted communications via a crafted certificate.
4.3
2017-08-02 CVE-2017-2278 Improper Certificate Validation vulnerability in IID RBB Speed Test
The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version 2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
4.3
2017-07-20 CVE-2017-7068 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
network
apple CWE-119
6.8
2017-07-20 CVE-2017-7064 Improper Input Validation vulnerability in Apple Iphone OS, Itunes and Safari
An issue was discovered in certain Apple products.
4.3
2017-07-20 CVE-2017-7063 Resource Exhaustion vulnerability in Apple Iphone OS and Watchos
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-400
5.0