Apple
apple
8,695 CVEs • 196 products
Products (196)
Click to collapseToggle
Products (196)
Click to collapse
CVEs (8,695)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, rela...Show more |
Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory con...Show more |
Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file. |
3Apple CanonicalWebkitgtk3Iphone Os Ubuntu LinuxWebkitgtkApr 29, 2026 Sep 9, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash)...Show more |
3Apple CanonicalWebkitgtk3Iphone Os Ubuntu LinuxWebkitgtkApr 29, 2026 Sep 9, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vector...Show more |
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outli...Show more |
3Apple CanonicalWebkitgtk3Iphone Os Ubuntu LinuxWebkitgtkApr 29, 2026 Sep 9, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash)...Show more |
ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF file. |
FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate. |
The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch does not perform the expected VoiceOver announcement associated with the location services icon, which has unspecified impact and attack ve...Show more |
2Apple Canonical2Iphone Os Ubuntu LinuxApr 29, 2026 Sep 9, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rende...Show more |
4Apple CanonicalGoogle+1 more5Chrome Iphone OsSafari+2 moreApr 29, 2026 Sep 7, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allow...Show more |
4Apple CanonicalGoogle+1 more5Chrome Iphone OsSafari+2 moreApr 29, 2026 Sep 7, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause...Show more |
2Apple Microsoft4Itunes Visual C#Visual Studio+1 moreMay 28, 2026 Aug 31, 2010 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Excha...Show more |
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unm...Show more |
1Apple 3Apple Type Services Mac Os XMac Os X ServerApr 29, 2026 Aug 25, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font...Show more |
1Apple 3Libsecurity Mac Os XMac Os X ServerApr 29, 2026 Aug 25, 2010 N/A· v4 N/A· v3 6.4 MEDIUM· v2 libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associat...Show more |
1Apple 3Coregraphics Mac Os XMac Os X ServerApr 29, 2026 Aug 25, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file. |
1Apple 3Cfnetwork Mac Os XMac Os X ServerApr 29, 2026 Aug 25, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses. |
4Apple CanonicalGoogle+1 more5Chrome Iphone OsSafari+2 moreApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary co...Show more |