<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apple iPhone</title>
  <link>https://cvedaily.com/pages/tags/iphone.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/iphone.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apple iPhone</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:49 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-28963 – A privacy issue was addressed by removing the vulnerable code. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28963</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28963</strong></p>
  <p>A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensitive user data during iPhone Mirroring.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25645 – WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25645</guid>
    <pubDate>Tue, 24 Mar 2026 12:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25645</strong></p>
  <p>WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-226</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20640 – An inconsistent user interface issue was addressed with improved state managemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20640</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20640</strong></p>
  <p>An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone during iPhone Mirroring with Mac.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53735 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53735</guid>
    <pubDate>Mon, 05 Jan 2026 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53735</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone Webclip Manager iphone-webclip-manager allows Stored XSS.This issue affects iPhone Webclip Manager: from n/a through <= 0.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50053 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50053</guid>
    <pubDate>Wed, 31 Dec 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50053</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App: from n/a through <= 0.8.8.8.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9200 – The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9200</guid>
    <pubDate>Fri, 03 Oct 2025 12:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9200</strong></p>
  <p>The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQL Injection via the nh_ynaa_comments() function in all versions up to, and including, 0.8.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43264 – Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43264</guid>
    <pubDate>Wed, 16 Nov 2022 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43264</strong></p>
  <p>Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43263 – A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43263</guid>
    <pubDate>Wed, 16 Nov 2022 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43263</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26959 – There are two full (read/write) Blind/Time-based SQL injection vulnerabilities i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26959</guid>
    <pubDate>Fri, 16 Sep 2022 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26959</strong></p>
  <p>There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. Exploitation of the SQL injection vulnerabilities allows full…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25071 – A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25071</guid>
    <pubDate>Sat, 25 Jun 2022 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25071</strong></p>
  <p>A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit details have been disclosed to the public. The existence and implications of this vulnerability are doubted by Apple even thou…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34409 – It was discovered that the installation packages of the Zoom Client for Meetings...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34409</guid>
    <pubDate>Mon, 27 Sep 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34409</strong></p>
  <p>It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-21301 – Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21301</guid>
    <pubDate>Thu, 11 Feb 2021 18:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-21301</strong></p>
  <p>Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in ver…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1894 – A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Busin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1894</guid>
    <pubDate>Thu, 03 Sep 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1894</strong></p>
  <p>A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.20.30 could have allowed arbitrary code execution when playing a specially crafted push to talk message.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-1891 – A user controlled parameter used in video call in WhatsApp for Android prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1891</guid>
    <pubDate>Thu, 03 Sep 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-1891</strong></p>
  <p>A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, WhatsApp for iPhone prior to v2.20.20, and WhatsApp Business for iPhone prior to v2.20.20 could have allowed an out-of-bounds write on 32-bit devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-6812 – The first time AirPods are connected to an iPhone, they become named after the u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6812</guid>
    <pubDate>Wed, 25 Mar 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-6812</strong></p>
  <p>The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thun…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18426 – A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18426</guid>
    <pubDate>Tue, 21 Jan 2020 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18426</strong></p>
  <p>A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-9536 – Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9536</guid>
    <pubDate>Fri, 22 Nov 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-9536</strong></p>
  <p>Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2018-17500 – Envoy Passport for Android and Envoy Passport for iPhone could allow a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17500</guid>
    <pubDate>Thu, 21 Mar 2019 16:00:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2018-17500</strong></p>
  <p>Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.</p>
  <p><strong>CVSS:</strong> 2.9 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2018-17499 – Envoy Passport for Android and Envoy Passport for iPhone could allow a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17499</guid>
    <pubDate>Thu, 21 Mar 2019 16:00:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2018-17499</strong></p>
  <p>Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.</p>
  <p><strong>CVSS:</strong> 2.9 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-4172 – An issue was discovered in certain Apple products. iOS before 11.3 is affected. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-4172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-4172</guid>
    <pubDate>Tue, 03 Apr 2018 06:29:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-4172</strong></p>
  <p>An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Find My iPhone" component. It allows physically proximate attackers to bypass the iCloud password requirement for disabling the "Find My iPhone" feature via vectors involving a backup restore.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-4172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2017-2730 – HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2730</guid>
    <pubDate>Wed, 22 Nov 2017 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2017-2730</strong></p>
  <p>HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier before 5.0.0 have an information leak vulnerability. When an iPhone with these APPs installed access the Wi-Fi hotpot built by attacker, the attacker can collect the information of iPhone mode and firmware version.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8248 – A buffer overflow may occur in the processing of a downlink NAS message in Qualc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8248</guid>
    <pubDate>Wed, 16 Aug 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8248</strong></p>
  <p>A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5913 – The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certifica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5913</guid>
    <pubDate>Fri, 05 May 2017 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5913</strong></p>
  <p>The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5912 – The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5912</guid>
    <pubDate>Fri, 05 May 2017 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5912</strong></p>
  <p>The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1776 – Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1776</guid>
    <pubDate>Mon, 24 Apr 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1776</strong></p>
  <p>Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to wipe the device.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-1187 – Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1187</guid>
    <pubDate>Fri, 21 Apr 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-1187</strong></p>
  <p>Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4829 – DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4829</guid>
    <pubDate>Fri, 21 Apr 2017 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4829</strong></p>
  <p>DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-2352 – An issue was discovered in certain Apple products. iOS before 10.2.1 is affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2352</guid>
    <pubDate>Mon, 20 Feb 2017 08:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-2352</strong></p>
  <p>An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Unlock with iPhone" component, which allows attackers to bypass the wrist-presence protection mechanism and unlock a Watch device via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7638 – An issue was discovered in certain Apple products. iOS before 10.2 is affected. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7638</guid>
    <pubDate>Mon, 20 Feb 2017 08:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7638</strong></p>
  <p>An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Find My iPhone" component, which allows physically proximate attackers to disable this component by bypassing authentication.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-1350 – Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1350</guid>
    <pubDate>Tue, 01 Jul 2014 10:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-1350</strong></p>
  <p>Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-2019 – The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2019</guid>
    <pubDate>Tue, 18 Feb 2014 11:55:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-2019</strong></p>
  <p>The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different Apple ID account, by entering an arbitrary iCloud Account Password value and a blank iCloud Account Description value.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-5726 – Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5726</guid>
    <pubDate>Tue, 12 Nov 2013 20:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-5726</strong></p>
  <p>Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-5162 – Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically prox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5162</guid>
    <pubDate>Thu, 24 Oct 2013 03:48:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-5162</strong></p>
  <p>Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass the passcode-failure disabled state by leveraging certain incorrect visibility of the passcode-entry view after use of the Phone app.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-5144 – Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically prox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5144</guid>
    <pubDate>Thu, 24 Oct 2013 03:48:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-5144</strong></p>
  <p>Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by tapping the emergency-call button during a certain notification and camera-pane state to trigger a NULL pointer dereference.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-5160 – Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically prox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5160</guid>
    <pubDate>Sat, 28 Sep 2013 03:40:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-5160</strong></p>
  <p>Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of taps of the emergency-call button to trigger a NULL pointer dereference.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-5224 – Untrusted search path vulnerability in Cool iPhone Ringtone Maker 2.2.3 allows l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-5224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-5224</guid>
    <pubDate>Thu, 06 Sep 2012 10:41:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-5224</strong></p>
  <p>Untrusted search path vulnerability in Cool iPhone Ringtone Maker 2.2.3 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .mp3 file.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-5224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2648 – Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2648</guid>
    <pubDate>Tue, 07 Aug 2012 19:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2648</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier for iOS on the iPad, and 3.15.1 and earlier for iOS on the iPhone and iPod touch, allows remote attackers to inject arbitrary web script or HTML via vectors involving use of this app in conjunction with a web browser.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-1327 – dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1327</guid>
    <pubDate>Thu, 03 May 2012 20:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-1327</strong></p>
  <p>dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (assertion failure and reboot) via 802.11 wireless traffic, as demonstrated by a video call from Apple iOS 5.0 on an iPhone 4S, aka Bug ID CSCtt94391.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1417 – Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and Mobil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1417</guid>
    <pubDate>Fri, 11 Mar 2011 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1417</strong></p>
  <p>Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the i…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1344 – Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1344</guid>
    <pubDate>Thu, 10 Mar 2011 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1344</strong></p>
  <p>Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding children to a WBR tag and then removing the tag, related to text nodes, as demonstrated by Chaouki Bekrar during a Pwn2Own competition at CanSecWest 2…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4552 – Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4552</guid>
    <pubDate>Thu, 16 Dec 2010 20:00:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4552</strong></p>
  <p>Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers to cause a denial of service (memory consumption and daemon outage) by sending many embedded objects in e-mail messages for iPhone clients.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2010-4548 – IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4548</guid>
    <pubDate>Thu, 16 Dec 2010 20:00:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2010-4548</strong></p>
  <p>IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and then accepting this meeting invitation with an iPhone client.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4012 – Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4012</guid>
    <pubDate>Wed, 08 Dec 2010 20:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4012</strong></p>
  <p>Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-3832 – Heap-based buffer overflow in the GSM mobility management implementation in Tele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3832</guid>
    <pubDate>Fri, 26 Nov 2010 20:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-3832</strong></p>
  <p>Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband processor via a crafted Temporary Mobile Subscriber Identity (TMSI) field.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1817 – Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1817</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1817</strong></p>
  <p>Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1815 – Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1815</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1815</strong></p>
  <p>Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1814 – WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1814</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1814</strong></p>
  <p>WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1813 – WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1813</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1813</strong></p>
  <p>WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outlines.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1812 – Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1812</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1812</strong></p>
  <p>Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selections.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1811 – ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1811</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1811</strong></p>
  <p>ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF file.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2010-1810 – FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1810</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2010-1810</strong></p>
  <p>FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1809 – The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1809</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1809</strong></p>
  <p>The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch does not perform the expected VoiceOver announcement associated with the location services icon, which has unspecified impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1781 – Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1781</guid>
    <pubDate>Thu, 09 Sep 2010 22:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1781</strong></p>
  <p>Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1768 – Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1768</guid>
    <pubDate>Fri, 20 Aug 2010 20:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1768</strong></p>
  <p>Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1797 – Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1797</guid>
    <pubDate>Mon, 16 Aug 2010 18:39:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1797</strong></p>
  <p>Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fon…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-2973 – Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2973</guid>
    <pubDate>Thu, 05 Aug 2010 18:17:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-2973</strong></p>
  <p>Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2010-1775 – Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod tou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1775</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2010-1775</strong></p>
  <p>Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving the initial boot.</p>
  <p><strong>CVSS:</strong> 1.9 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1757 – WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1757</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1757</strong></p>
  <p>WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user interface via a crafted HTML document.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1756 – The Settings application in Apple iOS before 4 on the iPhone and iPod touch does...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1756</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1756</strong></p>
  <p>The Settings application in Apple iOS before 4 on the iPhone and iPod touch does not properly report the wireless network that is in use, which might make it easier for remote attackers to trick users into communicating over an unintended network.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1755 – Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly impl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1755</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1755</strong></p>
  <p>Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the Accept Cookies preference, which makes it easier for remote web servers to track users via a cookie.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1754 – Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not proper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1754</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1754</strong></p>
  <p>Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote Lock operations through MobileMe, which allows physically proximate attackers to bypass intended passcode requirements via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1753 – ImageIO in Apple iOS before 4 on the iPhone and iPod touch allows remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1753</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1753</strong></p>
  <p>ImageIO in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG image.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1752 – Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1752</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1752</strong></p>
  <p>Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to URL handling.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1751 – Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1751</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1751</strong></p>
  <p>Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not prevent photo-library access, which might allow remote attackers to obtain location information via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1407 – WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly impl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1407</guid>
    <pubDate>Tue, 22 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1407</strong></p>
  <p>WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-2332 – Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2332</guid>
    <pubDate>Fri, 18 Jun 2010 20:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-2332</strong></p>
  <p>Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1769 – WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1769</guid>
    <pubDate>Fri, 18 Jun 2010 16:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1769</strong></p>
  <p>WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1387 – Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1387</guid>
    <pubDate>Fri, 18 Jun 2010 16:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1387</strong></p>
  <p>Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1226 – The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1226</guid>
    <pubDate>Thu, 01 Apr 2010 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1226</strong></p>
  <p>The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard crash) via a crafted innerHTML property of a DIV element, related to a "malformed character" issue.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1181 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1181</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1181</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a MARQUEE element.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1180 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1180</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1180</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1179 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1179</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1179</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a related issue to CVE-2007-0024.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1178 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1178</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1178</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinitely long string.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1177 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1177</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1177</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1176 – Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1176</guid>
    <pubDate>Mon, 29 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1176</strong></p>
  <p>Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttribute…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1119 – Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1119</guid>
    <pubDate>Thu, 25 Mar 2010 21:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1119</strong></p>
  <p>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo a…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1029 – Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1029</guid>
    <pubDate>Fri, 19 Mar 2010 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1029</strong></p>
  <p>Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-0496 – FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0496</guid>
    <pubDate>Wed, 03 Feb 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-0496</strong></p>
  <p>FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-0038 – Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0038</guid>
    <pubDate>Wed, 03 Feb 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-0038</strong></p>
  <p>Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-3936 – Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3936</guid>
    <pubDate>Fri, 13 Nov 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-3936</strong></p>
  <p>Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3273 – iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3273</guid>
    <pubDate>Mon, 21 Sep 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3273</strong></p>
  <p>iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-3271 – Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3271</guid>
    <pubDate>Mon, 21 Sep 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-3271</strong></p>
  <p>Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2815 – The Telephony component in Apple iPhone OS before 3.1 does not properly handle S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2815</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2815</strong></p>
  <p>The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer dereference and service interruption) via a crafted SMS message.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2797 – The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2797</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2797</strong></p>
  <p>The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2009-2796 – The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2796</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2009-2796</strong></p>
  <p>The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2795 – Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2795</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2795</strong></p>
  <p>Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to "command parsing."</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2794 – The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2794</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2794</strong></p>
  <p>The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2009-2207 – The MobileMail component in Apple iPhone OS 3.0 and 3.0.1, and iPhone OS 3.0 for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2207</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2009-2207</strong></p>
  <p>The MobileMail component in Apple iPhone OS 3.0 and 3.0.1, and iPhone OS 3.0 for iPod touch, lists deleted e-mail messages in Spotlight search results, which might allow local users to obtain sensitive information by reading these messages.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2206 – Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2206</guid>
    <pubDate>Thu, 10 Sep 2009 21:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2206</strong></p>
  <p>Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted (1) AAC or (2) MP3 file, as demonstrated by a ringtone with malformed entries in the sample size table.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2199 – Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2199</guid>
    <pubDate>Wed, 12 Aug 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2199</strong></p>
  <p>Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-2204 – Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2204</guid>
    <pubDate>Mon, 03 Aug 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-2204</strong></p>
  <p>Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS message that triggers memory corruption, as demonstrated by Charlie Miller at SyScan '09 Singapore.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1725 – WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1725</guid>
    <pubDate>Thu, 09 Jul 2009 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1725</strong></p>
  <p>WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cra…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-1724 – Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1724</guid>
    <pubDate>Thu, 09 Jul 2009 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-1724</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1692 – WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1692</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1692</strong></p>
  <p>WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page containing an HTMLSelectElement object with a large length attribute, related to the length property of a Select object.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1683 – The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1683</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1683</strong></p>
  <p>The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted ICMP echo request, which triggers an assertion error related to a "logic issue."</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2009-1680 – Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1680</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2009-1680</strong></p>
  <p>Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows physically proximate attackers to obtain the search history.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2009-1679 – The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1679</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2009-1679</strong></p>
  <p>The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange ActiveSync with a weaker password policy, which allows physically proximate attackers to bypass the intended policy.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-0961 – The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0961</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-0961</strong></p>
  <p>The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-0960 – The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0960</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-0960</strong></p>
  <p>The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0959 – The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0959</guid>
    <pubDate>Fri, 19 Jun 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0959</strong></p>
  <p>The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted MPEG-4 video file that triggers an "input validation issue."</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0959">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
