Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2013-01-29 CVE-2013-0953 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0952 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0951 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0950 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0949 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0948 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-21 CVE-2012-2291 Permissions, Privileges, and Access Controls vulnerability in EMC Avamar and Avamar Plugin
EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.
local
low complexity
emc apple hp CWE-264
7.2
2013-01-11 CVE-2013-0630 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe products
Buffer overflow in Adobe Flash Player before 10.3.183.50 and 11.x before 11.5.502.146 on Windows and Mac OS X, before 10.3.183.50 and 11.x before 11.2.202.261 on Linux, before 11.1.111.31 on Android 2.x and 3.x, and before 11.1.115.36 on Android 4.x; Adobe AIR before 3.5.0.1060; and Adobe AIR SDK before 3.5.0.1060 allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
adobe apple linux microsoft google CWE-119
critical
10.0
2012-12-12 CVE-2012-5678 Buffer Errors vulnerability in Adobe Air, AIR SDK and Flash Player
Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before 11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x; Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
network
low complexity
adobe microsoft linux google apple CWE-119
critical
10.0
2012-12-12 CVE-2012-5677 Numeric Errors vulnerability in Adobe Air, AIR SDK and Flash Player
Integer overflow in Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before 11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x; Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
adobe microsoft linux google apple CWE-189
critical
10.0