Vulnerabilities > Apple > Tvos > Low

DATE CVE VULNERABILITY TITLE RISK
2014-09-18 CVE-2014-4371 Improper Initialization vulnerability in Apple Iphone OS, mac OS X and Tvos
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4419, CVE-2014-4420, and CVE-2014-4421.
local
apple CWE-665
1.9
2014-09-18 CVE-2014-4372 Link Following vulnerability in Apple Iphone OS and Tvos
syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.
local
low complexity
apple CWE-59
3.6
2014-09-18 CVE-2014-4419 Security vulnerability in Apple Iphone OS, mac OS X and Tvos
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4420, and CVE-2014-4421.
local
apple
1.9
2014-09-18 CVE-2014-4420 Security vulnerability in Apple Iphone OS, mac OS X and Tvos
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4421.
local
apple
1.9
2014-09-18 CVE-2014-4421 Security vulnerability in Apple Iphone OS, mac OS X and Tvos
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4420.
local
apple
1.9
2014-03-14 CVE-2014-1279 Permissions, Privileges, and Access Controls vulnerability in Apple Tvos
Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.
local
low complexity
apple CWE-264
2.1
2013-03-20 CVE-2013-0978 Information Exposure vulnerability in Apple Iphone OS and Tvos
The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.
local
low complexity
apple CWE-200
2.1
2013-01-29 CVE-2013-0964 Improper Input Validation vulnerability in Apple Iphone OS and Tvos
The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a length of less than one page.
local
low complexity
apple CWE-20
3.6