FAIL › dossier
IOS
PRODUCT· dossier confidence 20%
IOS and Apple iOS both demonstrate a concerning track record of high-severity remote code execution vulnerabilities, with IOS plagued by decades-old unpatched flaws actively exploited in the wild and Apple iOS suffering repeated WebKit memory corruption and type confusion bugs. Organizations relying on either platform face significant risk from legacy vulnerabilities and frequent memory safety issues in core components.
Both IOS and Apple iOS have a history of high-severity remote code execution (RCE) vulnerabilities, with IOS suffering from decades-old unpatched flaws actively exploited in the wild, and Apple iOS experiencing repeated WebKit memory corruption and type confusion bugs leading to code execution.
- CVE-2008-4128: Decades-old Cisco IOS CSRF RCE actively exploited
- CVE-2022-42856: Apple iOS type confusion RCE
- CVE-2021-30761: Apple iOS WebKit memory corruption RCE
- CVE-2019-7287: Apple iOS memory corruption RCE
- CVE-2017-6744: Cisco IOS SNMP RCE
- CVE-2016-4656: Apple iOS kernel memory corruption RCE
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-05-24 | CVE-2016-4657 | high | Apple iOS WebKit memory corruption flaw allows remote code execution via malicious websites. |
| 2022-05-24 | CVE-2016-4656 | high | A memory corruption vulnerability in the iOS kernel allowed attackers to execute privileged code or cause DoS via a crafted app. |
| 2022-05-24 | CVE-2016-4655 | high | An iOS kernel vulnerability allowed attackers to read sensitive memory data via a crafted app, and it was actively exploited in the wild. |
| 2022-03-03 | CVE-2018-0180 | high | A decades-old Cisco IOS DoS vulnerability (CVE-2018-0180) remains actively exploited in the wild, proving that unpatched legacy hardware is a critical compliance failure. |
| 2021-11-03 | CVE-2021-30762 | high | Apple iOS WebKit use-after-free flaw allows remote code execution via malicious web content. |
| 2021-11-03 | CVE-2021-30761 | high | Apple iOS WebKit memory corruption vulnerability allows remote code execution via malicious web content. |
| 2021-11-03 | CVE-2021-30666 | high | Apple iOS WebKit buffer overflow allows remote code execution via malicious web content. |
| 2022-05-23 | CVE-2019-7287 | high | Apple iOS memory corruption vulnerability allows remote code execution and is actively exploited in the wild. |
| 2022-03-03 | CVE-2017-6744 | high | Cisco IOS software contained an SNMP remote code execution vulnerability allowing authenticated attackers to execute arbitrary code or reload systems via crafted packets. |
| 2023-05-19 | CVE-2004-1464 | high | Cisco IOS Denial-of-Service Vulnerability |
| 2022-12-14 | CVE-2022-42856 | high | Apple iOS had an active web content execution flaw |
| 2026-07-13 | CVE-2008-4128 | high | Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution. |
| 2022-03-03 | CVE-2017-12235 | high | An unauthenticated remote attacker could cause Cisco Industrial Ethernet switches to reload via a PROFINET protocol vulnerability, causing denial of service. |
| 2022-03-03 | CVE-2018-0154 | high | Cisco ISM-VPN crypto engine DoS vulnerability allowed unauthenticated remote attackers to crash devices, marking it as actively exploited in the KEV catalog. |
| 2022-03-03 | CVE-2018-0161 | high | Cisco IOS Software SNMP subsystem allowed authenticated remote attackers to cause denial-of-service via resource management errors. |
| 2022-03-03 | CVE-2018-0179 | high | Cisco IOS Software's Login Enhancements feature allowed unauthenticated remote attackers to trigger system reloads via a DoS vulnerability. |
| 2022-03-03 | CVE-2017-12232 | high | An unauthenticated adjacent attacker could force Cisco ISR G2 routers to reload via a DoS vulnerability in Cisco IOS. |
| 2022-03-03 | CVE-2017-12234 | high | Cisco IOS CIP vulnerability allows remote denial-of-service via unauthenticated requests causing device reloads. |
| 2022-03-03 | CVE-2017-12233 | high | Cisco IOS CIP vulnerability allows remote denial-of-service via unauthenticated requests causing device reloads. |
| 2022-03-03 | CVE-2017-12231 | high | Cisco IOS NAT DoS vulnerability allowed unauthenticated remote attackers to cause denial of service. |
- Apple Inc. (AAPL) Company Profile - Business Overview, Management Team ... · stocknear.com
- Apple (AAPL) Company Profile & Description - Stock Analysis · stockanalysis.com
- iOS zero-day exposure since 2007: what it means for defenders · nhimg.org
- CVE-2008-4128 - Cisco IOS Cross-Site Request Forgery Vulnerability ... · cvefeed.io
- CISA Warns of Decades Old Cisco IOS Vulnerability Actively Exploited in ... · cybersecuritynews.com
- Internetwork Operating System · whirlpool.net.au
- Timeline - The Apple Wiki · theapplewiki.com
- IOS: Releases, patches & end-of-life · www.versio.io