Vulnerabilities > Apple > Critical

DATE CVE VULNERABILITY TITLE RISK
2014-09-18 CVE-2014-4389 Numeric Errors vulnerability in Apple Iphone OS, mac OS X and Tvos
Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted API arguments.
network
apple CWE-189
critical
9.3
2014-09-18 CVE-2014-4388 Improper Input Validation vulnerability in Apple Iphone OS, mac OS X and Tvos
IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4418.
network
apple CWE-20
critical
9.3
2014-09-18 CVE-2014-4381 Buffer Errors vulnerability in Apple Iphone OS, mac OS X and Tvos
Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.
network
apple CWE-119
critical
9.3
2014-09-18 CVE-2014-4380 Buffer Errors vulnerability in Apple Iphone OS, mac OS X and Tvos
The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code in the kernel's context via a crafted application.
network
apple CWE-119
critical
9.3
2014-09-17 CVE-2014-0567 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0561.
network
low complexity
adobe apple microsoft CWE-119
critical
10.0
2014-09-17 CVE-2014-0565 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0566.
network
low complexity
adobe apple microsoft CWE-119
critical
10.0
2014-09-17 CVE-2014-0561 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0567.
network
low complexity
adobe apple microsoft CWE-119
critical
10.0
2014-09-17 CVE-2014-0560 Resource Management Errors vulnerability in Adobe Acrobat and Acrobat Reader
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
adobe apple microsoft CWE-399
critical
10.0
2014-09-10 CVE-2014-0554 Security Bypass vulnerability in Adobe Air, Adobe AIR SDK and Flash Player
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.
network
low complexity
adobe google apple microsoft linux
critical
10.0
2014-09-10 CVE-2014-0559 Buffer Errors vulnerability in Adobe Air, Adobe AIR SDK and Flash Player
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0556.
network
low complexity
adobe apple microsoft google linux CWE-119
critical
10.0