<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apple iPhone (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/iphone.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/iphone-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apple iPhone (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:49 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-53735 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53735</guid>
    <pubDate>Mon, 05 Jan 2026 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53735</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone Webclip Manager iphone-webclip-manager allows Stored XSS.This issue affects iPhone Webclip Manager: from n/a through <= 0.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50053 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50053</guid>
    <pubDate>Wed, 31 Dec 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50053</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App: from n/a through <= 0.8.8.8.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9200 – The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9200</guid>
    <pubDate>Fri, 03 Oct 2025 12:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9200</strong></p>
  <p>The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQL Injection via the nh_ynaa_comments() function in all versions up to, and including, 0.8.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43264 – Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43264</guid>
    <pubDate>Wed, 16 Nov 2022 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43264</strong></p>
  <p>Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26959 – There are two full (read/write) Blind/Time-based SQL injection vulnerabilities i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26959</guid>
    <pubDate>Fri, 16 Sep 2022 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26959</strong></p>
  <p>There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. Exploitation of the SQL injection vulnerabilities allows full…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34409 – It was discovered that the installation packages of the Zoom Client for Meetings...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34409</guid>
    <pubDate>Mon, 27 Sep 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34409</strong></p>
  <p>It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1894 – A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Busin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1894</guid>
    <pubDate>Thu, 03 Sep 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1894</strong></p>
  <p>A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.20.30 could have allowed arbitrary code execution when playing a specially crafted push to talk message.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-1891 – A user controlled parameter used in video call in WhatsApp for Android prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1891</guid>
    <pubDate>Thu, 03 Sep 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-1891</strong></p>
  <p>A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, WhatsApp for iPhone prior to v2.20.20, and WhatsApp Business for iPhone prior to v2.20.20 could have allowed an out-of-bounds write on 32-bit devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18426 – A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18426</guid>
    <pubDate>Tue, 21 Jan 2020 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18426</strong></p>
  <p>A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8248 – A buffer overflow may occur in the processing of a downlink NAS message in Qualc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8248</guid>
    <pubDate>Wed, 16 Aug 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8248</strong></p>
  <p>A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1809 – The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1809</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1809</strong></p>
  <p>The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch does not perform the expected VoiceOver announcement associated with the location services icon, which has unspecified impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1797 – Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1797</guid>
    <pubDate>Mon, 16 Aug 2010 18:39:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1797</strong></p>
  <p>Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fon…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1769 – WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1769</guid>
    <pubDate>Fri, 18 Jun 2010 16:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1769</strong></p>
  <p>WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1387 – Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1387</guid>
    <pubDate>Fri, 18 Jun 2010 16:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1387</strong></p>
  <p>Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1180 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1180</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1180</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1179 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1179</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1179</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a related issue to CVE-2007-0024.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1177 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1177</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1177</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1176 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1176</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1176</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttribute…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1119 – Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1119</guid>
    <pubDate>Thu, 25 Mar 2010 21:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1119</strong></p>
  <p>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo a…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3273 – iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3273</guid>
    <pubDate>Mon, 21 Sep 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3273</strong></p>
  <p>iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2815 – The Telephony component in Apple iPhone OS before 3.1 does not properly handle S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2815</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2815</strong></p>
  <p>The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer dereference and service interruption) via a crafted SMS message.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2795 – Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2795</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2795</strong></p>
  <p>Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to "command parsing."</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-2204 – Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2204</guid>
    <pubDate>Mon, 03 Aug 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-2204</strong></p>
  <p>Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS message that triggers memory corruption, as demonstrated by Charlie Miller at SyScan '09 Singapore.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1725 – WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1725</guid>
    <pubDate>Thu, 09 Jul 2009 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1725</strong></p>
  <p>WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cra…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1692 – WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1692</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1692</strong></p>
  <p>WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page containing an HTMLSelectElement object with a large length attribute, related to the length property of a Select object.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1683 – The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1683</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1683</strong></p>
  <p>The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted ICMP echo request, which triggers an assertion error related to a "logic issue."</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0959 – The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0959</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0959</strong></p>
  <p>The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted MPEG-4 video file that triggers an "input validation issue."</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1701 – Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1701</guid>
    <pubDate>Wed, 10 Jun 2009 18:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1701</strong></p>
  <p>Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML container with elements that support the dir attribute.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1699 – The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1699</guid>
    <pubDate>Wed, 10 Jun 2009 18:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1699</strong></p>
  <p>The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1698 – WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1698</guid>
    <pubDate>Wed, 10 Jun 2009 18:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1698</strong></p>
  <p>WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1690 – Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1690</guid>
    <pubDate>Wed, 10 Jun 2009 14:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1690</strong></p>
  <p>Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elemen…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1687 – The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1687</guid>
    <pubDate>Wed, 10 Jun 2009 14:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1687</strong></p>
  <p>The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that triggers write access to an "offset of a NULL…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1686 – WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1686</guid>
    <pubDate>Wed, 10 Jun 2009 14:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1686</strong></p>
  <p>WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle constant (aka const) declarations in a type-conversion operation during JavaScript exception handling, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0945 – Array index error in the insertItemBefore method in WebKit, as used in Apple Saf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0945</guid>
    <pubDate>Wed, 13 May 2009 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0945</strong></p>
  <p>Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGT…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5315 – Directory traversal vulnerability in the web interface in Apple iPhone Configura...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5315</guid>
    <pubDate>Wed, 03 Dec 2008 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5315</strong></p>
  <p>Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbitrary files via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-4231 – Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4231</guid>
    <pubDate>Tue, 25 Nov 2008 23:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-4231</strong></p>
  <p>Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4227 – Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 cha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4227</guid>
    <pubDate>Tue, 25 Nov 2008 23:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4227</strong></p>
  <p>Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level than was previously used, which makes it easier for remote attackers to obtain sensitive information or hijack a connection by decrypting network traffic.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1586 – ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1586</guid>
    <pubDate>Tue, 25 Nov 2008 23:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1586</strong></p>
  <p>ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory consumption and device reset) via a crafted TIFF image.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3623 – Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3623</guid>
    <pubDate>Mon, 17 Nov 2008 18:18:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3623</strong></p>
  <p>Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-4211 – Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Offic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4211</guid>
    <pubDate>Fri, 10 Oct 2008 10:30:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-4211</strong></p>
  <p>Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3632 – Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3632</guid>
    <pubDate>Thu, 11 Sep 2008 01:13:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3632</strong></p>
  <p>Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3631 – Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3631</guid>
    <pubDate>Thu, 11 Sep 2008 01:13:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3631</strong></p>
  <p>Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3612 – The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3612</guid>
    <pubDate>Thu, 11 Sep 2008 01:13:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3612</strong></p>
  <p>The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2320 – Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2320</guid>
    <pubDate>Mon, 04 Aug 2008 01:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2320</strong></p>
  <p>Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long filename to the file management API.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2303 – Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2303</guid>
    <pubDate>Mon, 14 Jul 2008 18:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2303</strong></p>
  <p>Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2317 – WebCore in Apple Safari does not properly perform garbage collection of JavaScri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2317</guid>
    <pubDate>Mon, 14 Jul 2008 18:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2317</strong></p>
  <p>WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-0729 – Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0729</guid>
    <pubDate>Tue, 12 Feb 2008 21:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-0729</strong></p>
  <p>Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs a long string and an array containing long string elements, possibly a related issue to CVE-2006-3677.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-5450 – Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5450</guid>
    <pubDate>Sun, 14 Oct 2007 18:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-5450</strong></p>
  <p>Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of service (application crash), and enable filesystem browsing by the local user, via a certain TIFF file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-3753 – Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3753</guid>
    <pubDate>Thu, 27 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-3753</strong></p>
  <p>Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Service Discovery Protocol (SDP) packets, related to insufficient input validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-3944 – Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3944</guid>
    <pubDate>Mon, 23 Jul 2007 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-3944</strong></p>
  <p>Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via certain JavaScript regular expressions. NOTE: this issue was originally reported only for MobileSafari on the iPhone.  NOTE: it is not clear whethe…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-2399 – WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 perfo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2399</guid>
    <pubDate>Mon, 25 Jun 2007 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-2399</strong></p>
  <p>WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2399">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
