Total
5524 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-4707 | 1 Apple | 2 Iphone Os, Mac Os X | 2017-07-29 | 2.1 LOW | 4.0 MEDIUM |
CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors. | |||||
CVE-2016-4706 | 1 Apple | 1 Mac Os X | 2017-07-29 | 4.9 MEDIUM | 5.5 MEDIUM |
cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors. | |||||
CVE-2016-4709 | 1 Apple | 1 Mac Os X | 2017-07-29 | 7.2 HIGH | 7.8 HIGH |
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710. | |||||
CVE-2016-4710 | 1 Apple | 1 Mac Os X | 2017-07-29 | 7.2 HIGH | 7.8 HIGH |
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709. | |||||
CVE-2016-4711 | 1 Apple | 2 Iphone Os, Mac Os X | 2017-07-29 | 5.0 MEDIUM | 7.5 HIGH |
CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output. | |||||
CVE-2016-4713 | 1 Apple | 1 Mac Os X | 2017-07-29 | 4.3 MEDIUM | 5.3 MEDIUM |
CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access. | |||||
CVE-2016-4716 | 1 Apple | 1 Mac Os X | 2017-07-29 | 7.2 HIGH | 7.8 HIGH |
diskutil in DiskArbitration in Apple OS X before 10.12 allows local users to gain privileges via unspecified vectors. | |||||
CVE-2016-4715 | 1 Apple | 1 Mac Os X | 2017-07-29 | 4.3 MEDIUM | 3.3 LOW |
The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app. | |||||
CVE-2016-4717 | 1 Apple | 1 Mac Os X | 2017-07-29 | 5.0 MEDIUM | 3.3 LOW |
The File Bookmark component in Apple OS X before 10.12 mishandles scoped-bookmark file descriptors, which allows attackers to cause a denial of service via a crafted app. | |||||
CVE-2016-4722 | 1 Apple | 2 Iphone Os, Mac Os X | 2017-07-29 | 7.1 HIGH | 5.9 MEDIUM |
The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attacks and cause a denial of service via unspecified vectors. | |||||
CVE-2016-4723 | 1 Apple | 1 Mac Os X | 2017-07-29 | 9.3 HIGH | 7.8 HIGH |
Intel Graphics Driver in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | |||||
CVE-2016-4727 | 1 Apple | 1 Mac Os X | 2017-07-29 | 9.3 HIGH | 7.8 HIGH |
IOThunderboltFamily in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | |||||
CVE-2016-4739 | 1 Apple | 1 Mac Os X | 2017-07-29 | 4.3 MEDIUM | 3.7 LOW |
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface. | |||||
CVE-2016-4742 | 1 Apple | 1 Mac Os X | 2017-07-29 | 4.3 MEDIUM | 5.5 MEDIUM |
NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app. | |||||
CVE-2016-4748 | 1 Apple | 1 Mac Os X | 2017-07-29 | 4.6 MEDIUM | 5.3 MEDIUM |
Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable. | |||||
CVE-2016-4750 | 1 Apple | 2 Iphone Os, Mac Os X | 2017-07-29 | 9.3 HIGH | 7.8 HIGH |
S2 Camera in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | |||||
CVE-2016-4752 | 1 Apple | 1 Mac Os X | 2017-07-29 | 4.3 MEDIUM | 5.5 MEDIUM |
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation. | |||||
CVE-2016-4755 | 1 Apple | 1 Mac Os X | 2017-07-29 | 2.1 LOW | 5.5 MEDIUM |
Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-4771 | 1 Apple | 2 Iphone Os, Mac Os X | 2017-07-29 | 4.3 MEDIUM | 5.5 MEDIUM |
The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname. | |||||
CVE-2016-4779 | 1 Apple | 1 Mac Os X | 2017-07-29 | 6.8 MEDIUM | 7.8 HIGH |
Apple Type Services (ATS) in Apple OS X before 10.12 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file. |