← Back

Iphone Os

iphone_os

Vendor: Apple • 4,014 CVEs

CVEs (4,014)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Apple
Suse
4Iphone Os
Linux Enterprise DesktopLinux Enterprise Server+1 more
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in...Show more
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.Show less
2Apple
Google
3Chrome
Iphone OsSafari
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) t...Show more
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.Show less
2Apple
Google
4Android
ChromeIphone Os+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::cle...Show more
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ property, (3) the HTMLPlugInImageElement::allowedToLoadFrameURL function and use of a javascript: URL, (4) incorrect origins for XSLT-generated documents in the XSLTProcessor::createDocumentFromSource function, and (5) improper handling of synchronous frame loads in the ScriptController::executeIfJavaScriptURL function.Show less
2Apple
Google
3Chrome
Iphone OsSafari
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the de...Show more
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen.Show less
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified imp...Show more
The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.Show less
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, which might allow physically proximate attackers to obtain sensitive information by reading this file...Show more
The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, which might allow physically proximate attackers to obtain sensitive information by reading this file.Show less
1Apple
2Apple Tv
Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.6 LOW· v2
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof...Show more
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.Show less
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Excel spreadsheet.
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word document.
1Apple
2Apple Tv
Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remote attackers to cause a denial of service (resource consumption) by mak...Show more
The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remote attackers to cause a denial of service (resource consumption) by making many connection attempts.Show less
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic c...Show more
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a different account's cookie.Show less
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory co...Show more
FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a different vulnerability than CVE-2011-0226.Show less
1Apple
1Iphone Os
Apr 29, 2026
Oct 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.