Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-04-02 CVE-2014-1299 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Safari
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
network
apple CWE-119
6.8
2014-04-02 CVE-2014-1298 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Safari
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
network
apple CWE-119
6.8
2014-04-02 CVE-2014-1297 Improper Input Validation vulnerability in Apple Safari
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.
network
low complexity
apple CWE-20
5.0
2014-03-31 CVE-2014-0067 Permissions, Privileges, and Access Controls vulnerability in multiple products
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
local
low complexity
apple postgresql CWE-264
4.6
2014-03-14 CVE-2014-1294 Buffer Errors vulnerability in Apple Iphone OS and Tvos
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293.
network
apple CWE-119
6.8
2014-03-14 CVE-2014-1293 Buffer Errors vulnerability in Apple Iphone OS and Tvos
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1294.
network
apple CWE-119
6.8
2014-03-14 CVE-2014-1292 Buffer Errors vulnerability in Apple Iphone OS and Tvos
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.
network
apple CWE-119
6.8
2014-03-14 CVE-2014-1291 Buffer Errors vulnerability in Apple Iphone OS and Tvos
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
network
apple CWE-119
6.8
2014-03-14 CVE-2014-1290 Buffer Errors vulnerability in Apple Iphone OS and Tvos
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
network
apple CWE-119
6.8
2014-03-14 CVE-2014-1289 Buffer Errors vulnerability in Apple Iphone OS and Tvos
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.
network
apple CWE-119
6.8