Advisories
SafariWeaponized exploitHIGH2014-03-26
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.
CVEs:CVE-2014-1303
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
iOSWeaponized exploitMEDIUM2014-03-11
TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL.
CVEs:CVE-2013-6835
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
tvOSWeaponized exploitCRITICAL2014-03-11
USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.
CVEs:CVE-2014-1287
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2014-03-26
Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competition at CanSecWest 2014.
CVEs:CVE-2014-1300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2014-03-11
Buffer overflow in ImageIO in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.
CVEs:CVE-2014-1275
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2014-03-11
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-12...
CVEs:CVE-2014-1292
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2014-03-11
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-12...
CVEs:CVE-2014-1289
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2014-03-11
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-12...
CVEs:CVE-2014-1290
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2014-03-11
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-12...
CVEs:CVE-2014-1291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2014-03-11
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-12...
CVEs:CVE-2014-1293
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%CRITICAL2014-03-11
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-12...
CVEs:CVE-2014-1294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
iOSEPSS <= 49%HIGH2014-03-11
Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted backup data.
CVEs:CVE-2013-5133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
iOSEPSS <= 49%HIGH2014-03-11
SpringBoard Lock Screen in Apple iOS before 7.1 allows remote attackers to cause a denial of service (lock-screen hang) by leveraging a state-management error.
CVEs:CVE-2014-1286
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
tvOSEPSS <= 49%HIGH2014-03-11
Video Driver in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to cause a denial of service (NULL pointer dereference and device hang) via a crafted video file with MPEG-4 encoding.
CVEs:CVE-2014-1280
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%HIGH2014-03-11
CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of service (assertion failure and device crash) via a crafted app.
CVEs:CVE-2014-1271
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
iOSEPSS <= 49%MEDIUM2014-03-11
IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that accesses an IOKit framework interface.
CVEs:CVE-2014-1276
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
iOSEPSS <= 49%HIGH2014-03-11
Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.
CVEs:CVE-2014-1285
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
tvOSEPSS <= 49%MEDIUM2014-03-11
dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing requirements by leveraging use of text-relocation instructions in a dynamic library.
CVEs:CVE-2014-1273
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%MEDIUM2014-03-11
The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requirements via a long name.
CVEs:CVE-2014-1282
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
macOSEPSS <= 49%MEDIUM2014-03-05
A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify callback function's documentation, which allows remote ...
CVEs:CVE-2014-2234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
tvOSEPSS <= 49%MEDIUM2014-03-11
The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass intended access restrictions by using a profile afte...
CVEs:CVE-2014-1267
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
iOSEPSS <= 49%LOW2014-03-11
FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call.
CVEs:CVE-2014-1274
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
tvOSEPSS <= 49%MEDIUM2014-03-11
CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink.
CVEs:CVE-2014-1272
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
tvOSEPSS <= 49%HIGH2014-03-11
The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access and device crash) via a crafted call.
CVEs:CVE-2014-1278
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
iOSEPSS <= 49%LOW2014-03-11
Photos Backend in Apple iOS before 7.1 does not properly manage the asset-library cache during deletions, which allows physically proximate attackers to obtain sensitive photo data by launching the Photos app and looking under a transparent image.
CVEs:CVE-2014-1281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
OtherEPSS <= 49%MEDIUM2014-03-11
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
CVEs:CVE-2014-0106
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
tvOSEPSS <= 49%MEDIUM2014-03-11
Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.
CVEs:CVE-2014-1279
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tvos |
affected |
apple |
— |
— |