Latest CVE Feed
-
7.5
HIGHCVE-2016-4070
Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to cause a denial of service (application crash) via a long string to the rawurlencode functi... Read more
Affected Products : php- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1859
The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1858
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1857
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854,... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1856
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854,... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1855
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854,... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1854
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855,... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1853
Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
2.4
LOWCVE-2016-1852
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.... Read more
Affected Products : iphone_os- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2016-1851
The Screen Lock feature in Apple OS X before 10.11.5 mishandles password profiles, which allows physically proximate attackers to reset expired passwords in the lock-screen state via unspecified vectors.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1850
SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2016-1849
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1848
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1847
OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference and memory corruption... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1844
The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1843
The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1842
MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1841
libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1840
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a de... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025