<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apple iPad</title>
  <link>https://cvedaily.com/pages/tags/ipad.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ipad.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apple iPad</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-65882 – An issue was discovered in openmptcprouter thru 0.64 in file common/package/util...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65882</guid>
    <pubDate>Tue, 09 Dec 2025 19:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-65882</strong></p>
  <p>An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61836 – Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61836</guid>
    <pubDate>Tue, 11 Nov 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61836</strong></p>
  <p>Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61829 – Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61829</guid>
    <pubDate>Tue, 11 Nov 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61829</strong></p>
  <p>Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61828 – Illustrator on iPad versions 3.0.9 and earlier are affected by an out-of-bounds ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61828</guid>
    <pubDate>Tue, 11 Nov 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61828</strong></p>
  <p>Illustrator on iPad versions 3.0.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61827 – Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61827</guid>
    <pubDate>Tue, 11 Nov 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61827</strong></p>
  <p>Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61826 – Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61826</guid>
    <pubDate>Tue, 11 Nov 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61826</strong></p>
  <p>Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-21134 – Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21134</guid>
    <pubDate>Tue, 14 Jan 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-21134</strong></p>
  <p>Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-21133 – Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21133</guid>
    <pubDate>Tue, 14 Jan 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-21133</strong></p>
  <p>Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43264 – Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43264</guid>
    <pubDate>Wed, 16 Nov 2022 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43264</strong></p>
  <p>Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43263 – A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43263</guid>
    <pubDate>Wed, 16 Nov 2022 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43263</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34409 – It was discovered that the installation packages of the Zoom Client for Meetings...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34409</guid>
    <pubDate>Mon, 27 Sep 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34409</strong></p>
  <p>It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-21301 – Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21301</guid>
    <pubDate>Thu, 11 Feb 2021 18:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-21301</strong></p>
  <p>Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in ver…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-17502 – The Receptionist for iPad could allow a local attacker to obtain sensitive infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17502</guid>
    <pubDate>Thu, 21 Mar 2019 16:00:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-17502</strong></p>
  <p>The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contact.json file. An attacker could exploit this vulnerability to obtain the contact names, phone numbers and emails.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8248 – A buffer overflow may occur in the processing of a downlink NAS message in Qualc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8248</guid>
    <pubDate>Wed, 16 Aug 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8248</strong></p>
  <p>A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4829 – DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4829</guid>
    <pubDate>Fri, 21 Apr 2017 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4829</strong></p>
  <p>DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-2598 – Unspecified vulnerability in the mobile app in Oracle Business Intelligence Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2598</guid>
    <pubDate>Thu, 16 Jul 2015 10:59:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-2598</strong></p>
  <p>Unspecified vulnerability in the mobile app in Oracle Business Intelligence Enterprise Edition in Oracle Fusion Middleware before 11.1.1.7.0 (11.6.39) allows remote authenticated users to affect integrity via unknown vectors related to Mobile - iPad.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1151 – Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1151</guid>
    <pubDate>Tue, 28 Apr 2015 22:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1151</strong></p>
  <p>Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5555 – The Counting &amp; Addition Kids Games (aka air.com.tribalnova.ilearnwith.ipad.PokoA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5555</guid>
    <pubDate>Tue, 09 Sep 2014 01:55:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5555</strong></p>
  <p>The Counting & Addition Kids Games (aka air.com.tribalnova.ilearnwith.ipad.PokoAddEn) application 1.8.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5554 – The Fun Preschool Creativity Game (aka air.com.tribalnova.ilearnwith.ipad.Mother...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5554</guid>
    <pubDate>Tue, 09 Sep 2014 01:55:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5554</strong></p>
  <p>The Fun Preschool Creativity Game (aka air.com.tribalnova.ilearnwith.ipad.MotherAppEn) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5553 – The Kids Preschool Learning Games (aka air.com.tribalnova.ilearnwith.ipad.App3En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5553</guid>
    <pubDate>Tue, 09 Sep 2014 01:55:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5553</strong></p>
  <p>The Kids Preschool Learning Games (aka air.com.tribalnova.ilearnwith.ipad.App3En) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5552 – The Numbers &amp; Addition! Math games (aka air.com.tribalnova.ilearnwith.ipad.App2E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5552</guid>
    <pubDate>Tue, 09 Sep 2014 01:55:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5552</strong></p>
  <p>The Numbers & Addition! Math games (aka air.com.tribalnova.ilearnwith.ipad.App2En) application 1.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5551 – The Alphabet &amp; Spelling Kids Games (aka air.com.tribalnova.ilearnwith.ipad.App1E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5551</guid>
    <pubDate>Tue, 09 Sep 2014 01:55:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5551</strong></p>
  <p>The Alphabet & Spelling Kids Games (aka air.com.tribalnova.ilearnwith.ipad.App1En) application 1.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-1828 – The iThoughts web server in the iThoughtsHD app 4.19 for iOS on iPad devices all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1828</guid>
    <pubDate>Wed, 26 Mar 2014 10:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-1828</strong></p>
  <p>The iThoughts web server in the iThoughtsHD app 4.19 for iOS on iPad devices allows remote attackers to cause a denial of service (disk consumption) by uploading a large file.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-1827 – The iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1827</guid>
    <pubDate>Wed, 26 Mar 2014 10:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-1827</strong></p>
  <p>The iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature is used, allows remote attackers to upload arbitrary files by placing a %00 sequence after a dangerous extension, as demonstrated by a .html%00.txt file.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2014-1826 – Cross-site scripting (XSS) vulnerability in the iThoughtsHD app 4.19 for iOS on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1826</guid>
    <pubDate>Wed, 26 Mar 2014 10:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2014-1826</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature is used, allows remote attackers to inject arbitrary web script or HTML via a crafted map name.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2898 – Google Chrome before 21.0.1180.82 on iOS on iPad devices allows remote attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2898</guid>
    <pubDate>Sun, 05 Jan 2014 20:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2898</strong></p>
  <p>Google Chrome before 21.0.1180.82 on iOS on iPad devices allows remote attackers to spoof the Omnibox URL via vectors involving SSL error messages, a related issue to CVE-2012-0674.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-5726 – Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5726</guid>
    <pubDate>Tue, 12 Nov 2013 20:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-5726</strong></p>
  <p>Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-3955 – The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3955</guid>
    <pubDate>Wed, 05 Jun 2013 14:39:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-3955</strong></p>
  <p>The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2648 – Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2648</guid>
    <pubDate>Tue, 07 Aug 2012 19:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2648</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier for iOS on the iPad, and 3.15.1 and earlier for iOS on the iPhone and iPod touch, allows remote attackers to inject arbitrary web script or HTML via vectors involving use of this app in conjunction with a web browser.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2012-0800 – The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0800</guid>
    <pubDate>Tue, 17 Jul 2012 10:20:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2012-0800</strong></p>
  <p>The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2011-3440 – The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not prope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3440</guid>
    <pubDate>Fri, 11 Nov 2011 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2011-3440</strong></p>
  <p>The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.</p>
  <p><strong>CVSS:</strong> 1.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1344 – Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1344</guid>
    <pubDate>Thu, 10 Mar 2011 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1344</strong></p>
  <p>Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding children to a WBR tag and then removing the tag, related to text nodes, as demonstrated by Chaouki Bekrar during a Pwn2Own competition at CanSecWest 2…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-3832 – Heap-based buffer overflow in the GSM mobility management implementation in Tele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3832</guid>
    <pubDate>Fri, 26 Nov 2010 20:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-3832</strong></p>
  <p>Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband processor via a crafted Temporary Mobile Subscriber Identity (TMSI) field.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-2711 – Unspecified vulnerability in the HP MagCloud app before 1.0.5 for the iPad allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2711</guid>
    <pubDate>Wed, 25 Aug 2010 20:00:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-2711</strong></p>
  <p>Unspecified vulnerability in the HP MagCloud app before 1.0.5 for the iPad allows remote attackers to read and modify MagCloud application data via unknown vectors.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1768 – Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1768</guid>
    <pubDate>Fri, 20 Aug 2010 20:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1768</strong></p>
  <p>Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1797 – Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1797</guid>
    <pubDate>Mon, 16 Aug 2010 18:39:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1797</strong></p>
  <p>Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fon…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-2973 – Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2973</guid>
    <pubDate>Thu, 05 Aug 2010 18:17:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-2973</strong></p>
  <p>Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2973">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
