Vulnerabilities > Apple > Safari > 7.1

DATE CVE VULNERABILITY TITLE RISK
2015-09-18 CVE-2015-5791 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS, Itunes and Safari
WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
network
apple CWE-119
6.8
2015-09-18 CVE-2015-5790 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS, Itunes and Safari
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
network
apple CWE-119
6.8
2015-09-18 CVE-2015-5789 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS, Itunes and Safari
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
network
apple CWE-119
6.8
2015-09-18 CVE-2015-5788 Information Exposure vulnerability in Apple Iphone OS and Safari
The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.
network
apple CWE-200
4.3
2015-09-18 CVE-2015-5767 Improper Input Validation vulnerability in Apple Iphone OS and Safari
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.
network
apple CWE-20
4.3
2015-09-18 CVE-2015-5765 Improper Input Validation vulnerability in Apple Iphone OS and Safari
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.
network
apple CWE-20
4.3
2015-09-18 CVE-2015-5764 Improper Input Validation vulnerability in Apple Iphone OS and Safari
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767.
network
apple CWE-20
4.3
2015-09-18 CVE-2015-3801 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS and Safari
The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.
network
low complexity
apple CWE-264
5.0
2015-08-17 CVE-2015-5748 Code vulnerability in Apple Iphone OS, mac OS X and Safari
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.
local
low complexity
apple CWE-17
2.1
2015-08-16 CVE-2015-3755 7PK - Security Features vulnerability in Apple Iphone OS and Safari
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.
network
apple CWE-254
4.3