Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.8

    MEDIUM
    CVE-2016-1730

    WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.... Read more

    Affected Products : iphone_os
    • EPSS Score: %0.27
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-1729

    Untrusted search path vulnerability in OSA Scripts in Apple OS X before 10.11.3 allows attackers to load arbitrary script libraries via a quarantined application.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.49
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-1728

    The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain sensitive browser-history informati... Read more

    Affected Products : iphone_os safari
    • EPSS Score: %0.76
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1727

    WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1724.... Read more

    Affected Products : iphone_os tvos watchos safari webkitgtk\+
    • EPSS Score: %1.02
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1726

    WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1725.... Read more

    Affected Products : iphone_os watchos safari
    • EPSS Score: %1.70
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1725

    WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1726.... Read more

    Affected Products : iphone_os watchos safari
    • EPSS Score: %1.70
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-1724

    WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.... Read more

    Affected Products : iphone_os tvos watchos safari webkitgtk\+
    • EPSS Score: %1.01
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1723

    WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1725 and CVE-2016-1726.... Read more

    Affected Products : iphone_os watchos safari
    • EPSS Score: %1.70
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-1722

    syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x iphone_os tvos watchos
    • EPSS Score: %0.08
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-1721

    The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x iphone_os tvos watchos
    • EPSS Score: %0.24
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-1720

    IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x iphone_os tvos watchos
    • EPSS Score: %0.24
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-1719

    The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x iphone_os tvos watchos
    • EPSS Score: %0.30
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.3

    HIGH
    CVE-2016-1718

    The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.04
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-1717

    The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x iphone_os tvos watchos
    • EPSS Score: %0.08
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-1716

    AppleGraphicsPowerManagement in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.05
    • Published: Feb. 01, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-1948

    Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.... Read more

    Affected Products : android firefox
    • EPSS Score: %0.22
    • Published: Jan. 31, 2016
    • Modified: Apr. 12, 2025
  • 4.7

    MEDIUM
    CVE-2016-1947

    Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.... Read more

    Affected Products : firefox ubuntu_linux leap opensuse
    • EPSS Score: %0.60
    • Published: Jan. 31, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1946

    The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow)... Read more

    Affected Products : firefox leap opensuse
    • EPSS Score: %3.53
    • Published: Jan. 31, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1945

    The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.... Read more

    Affected Products : firefox leap opensuse
    • EPSS Score: %0.67
    • Published: Jan. 31, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1944

    The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.... Read more

    Affected Products : firefox leap opensuse
    • EPSS Score: %2.83
    • Published: Jan. 31, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291712 Results