Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-01-29 CVE-2013-0956 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0955 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0954 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0953 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0952 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0951 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0950 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0949 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2013-01-29 CVE-2013-0948 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
network
apple CWE-119
6.8
2012-11-15 CVE-2012-5851 Cross-Site Scripting vulnerability in multiple products
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.
network
apple google CWE-79
4.3