Vulnerabilities
Vulnerable Software
Apple:  >> Iphone Os  >> 1.0.1  Security Vulnerabilities
WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site.
CVSS Score
6.5
EPSS Score
0.007
Published
2016-03-24
WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.
CVSS Score
4.3
EPSS Score
0.005
Published
2016-03-24
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site.
CVSS Score
4.3
EPSS Score
0.003
Published
2016-03-24
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request.
CVSS Score
6.5
EPSS Score
0.077
Published
2016-03-24
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
CVSS Score
8.8
EPSS Score
0.009
Published
2016-03-24
TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
CVSS Score
7.8
EPSS Score
0.007
Published
2016-03-24
The Profiles component in Apple iOS before 9.3 does not properly validate certificates, which allows attackers to spoof an MDM profile trust relationship via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.001
Published
2016-03-24
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.
CVSS Score
3.5
EPSS Score
0.002
Published
2016-03-24
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
CVSS Score
8.1
EPSS Score
0.073
Published
2016-03-24
libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
CVSS Score
9.8
EPSS Score
0.11
Published
2016-03-24


Contact Us

Shodan ® - All rights reserved