Vulnerabilities > Apple > Tvos > 4.4.3

DATE CVE VULNERABILITY TITLE RISK
2014-09-18 CVE-2014-4378 Buffer Errors vulnerability in Apple Iphone OS, mac OS X and Tvos
CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted PDF document.
network
apple CWE-119
5.8
2014-09-18 CVE-2014-4377 Numeric Errors vulnerability in Apple Iphone OS, mac OS X and Tvos
Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
network
apple CWE-189
6.8
2014-09-18 CVE-2014-4375 Local Memory Corruption vulnerability in Apple Iphone OS, mac OS X and Tvos
Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.
local
low complexity
apple
7.2
2014-09-18 CVE-2014-4373 NULL Pointer Dereference Denial of Service vulnerability in Apple Iphone OS, mac OS X and Tvos
The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device restart) via a crafted application.
network
low complexity
apple
7.8
2014-09-18 CVE-2014-4372 Link Following vulnerability in Apple Iphone OS and Tvos
syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.
local
low complexity
apple CWE-59
3.6
2014-09-18 CVE-2014-4371 Improper Initialization vulnerability in Apple Iphone OS, mac OS X and Tvos
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4419, CVE-2014-4420, and CVE-2014-4421.
local
apple CWE-665
1.9
2014-09-18 CVE-2014-4369 NULL Pointer Dereference Denial of Service vulnerability in Apple Iphone OS and Tvos
The IOAcceleratorFamily API implementation in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via an application that uses crafted arguments.
network
low complexity
apple
7.8
2014-09-18 CVE-2014-4364 Cryptographic Issues vulnerability in Apple Iphone OS and Tvos
The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptographic attack against the MS-CHAPv1 hash.
2.9
2014-09-18 CVE-2014-4357 Information Exposure vulnerability in Apple Iphone OS and Tvos
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.
local
low complexity
apple CWE-200
2.1
2014-07-01 CVE-2014-1383 Permissions, Privileges, and Access Controls vulnerability in Apple Tvos
Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspecified vectors.
network
low complexity
apple CWE-264
5.5