Latest CVE Feed
-
5.3
MEDIUMCVE-2016-4713
CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.... Read more
- EPSS Score: %0.41
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4712
CoreCrypto in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.... Read more
- EPSS Score: %0.26
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4711
CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output.... Read more
- EPSS Score: %0.48
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-4710
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709.... Read more
- EPSS Score: %0.05
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-4709
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710.... Read more
- EPSS Score: %0.05
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-4708
CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.... Read more
- EPSS Score: %4.17
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2016-4707
CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.... Read more
- EPSS Score: %0.06
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-4706
cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors.... Read more
- EPSS Score: %0.14
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4703
Bluetooth in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more
- EPSS Score: %0.36
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4702
Audio in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more
- EPSS Score: %14.12
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
6.2
MEDIUMCVE-2016-4701
Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable.... Read more
- EPSS Score: %0.14
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4700
AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4699.... Read more
- EPSS Score: %0.36
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4699
AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4700.... Read more
- EPSS Score: %0.23
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4698
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.... Read more
- EPSS Score: %0.24
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4697
Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more
- EPSS Score: %0.22
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4696
AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.... Read more
- EPSS Score: %0.22
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-4694
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might all... Read more
- EPSS Score: %0.96
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4658
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or... Read more
- EPSS Score: %19.34
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4618
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."... Read more
- EPSS Score: %0.50
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-4611
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE... Read more
- EPSS Score: %0.92
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025