Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Filtered by product Ipod Touch
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4227 1 Apple 3 Iphone, Iphone Os, Ipod Touch 2011-09-21 7.5 HIGH N/A
Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level than was previously used, which makes it easier for remote attackers to obtain sensitive information or hijack a connection by decrypting network traffic.
CVE-2008-3612 1 Apple 2 Iphone, Ipod Touch 2011-06-20 7.5 HIGH N/A
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
CVE-2008-4229 1 Apple 3 Iphone, Iphone Os, Ipod Touch 2011-03-08 3.7 LOW N/A
Race condition in the Passcode Lock feature in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.0 through 2.1 allows physically proximate attackers to remove the lock and launch arbitrary applications by restoring the device from a backup.
CVE-2008-4233 1 Apple 4 Iphone, Iphone Os, Ipod Touch and 1 more 2011-03-08 2.6 LOW N/A
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.
CVE-2008-4230 1 Apple 3 Iphone, Iphone Os, Ipod Touch 2011-03-08 1.9 LOW N/A
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by reading these messages. NOTE: this might be a duplicate of CVE-2008-4593.
CVE-2008-4228 1 Apple 3 Iphone, Iphone Os, Ipod Touch 2011-03-08 3.6 LOW N/A
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows physically proximate attackers to leverage the emergency-call ability of locked devices to make a phone call to an arbitrary number.
CVE-2008-4232 1 Apple 4 Iphone, Iphone Os, Ipod Touch and 1 more 2011-03-08 5.0 MEDIUM N/A
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
CVE-2008-3631 1 Apple 1 Ipod Touch 2011-03-08 7.1 HIGH N/A
Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.
CVE-2008-1586 1 Apple 3 Iphone, Iphone Os, Ipod Touch 2011-03-08 7.1 HIGH N/A
ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory consumption and device reset) via a crafted TIFF image.
CVE-2010-2973 1 Apple 4 Ipad, Iphone, Iphone Os and 1 more 2010-08-18 6.9 MEDIUM N/A
Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe.