Vulnerability index

Browse CVEs

390 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Safari MEDIUM 6.5
CVE-2017-2442EPSS 6%

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaSc…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Safari MEDIUM 6.5
CVE-2017-2453

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" compo…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Mac Os X HIGH 7.8
CVE-2017-2410

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.12.3
Fix from $1,950 2017-04-02
Iphone Os MEDIUM 5.3
CVE-2017-2414

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "DataAccess" component. It allows remote attac…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Safari HIGH 8.8
CVE-2017-2378

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves bookmark creation …

Fix: after 10.2.1
Fix from $1,950 2017-04-02
Iphone Os MEDIUM 6.5
CVE-2017-2371EPSS 6%

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote atta…

Fix: 10.2.1+
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.5
CVE-2017-2368

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attac…

Fix: after 10.2.0
Fix from $1,600 2017-02-20
Mac Os X HIGH 7.8
CVE-2016-7742

An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" component, which allows remote atta…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Iphone Os HIGH 7.5
CVE-2016-7667

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreText" c…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Iphone Os MEDIUM 5.5
CVE-2016-7665

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Graphics Driver" component, which allows remo…

Fix: after 10.1.1
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.9
CVE-2016-7636

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 6.8
CVE-2016-4690

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Image Capture" component, which allows attack…

Fix: after 10.1.1
Fix from $1,600 2017-02-20
Mac Os X MEDIUM 6.5
CVE-2016-7580

An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves the "Mail" component, which allows remote web s…

Fix: after 10.11.6
Fix from $1,600 2017-02-20
Iphone Os HIGH 7.8
CVE-2016-4669

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat…

Fix: 3.1 / 10.0.1+
Fix from $1,950 2017-02-20
Mac Os X MEDIUM 5.5
CVE-2016-4661

An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" component, which misparses disk im…

Fix: after 10.12.0
Fix from $1,600 2017-02-20
Iphone Os HIGH 7.8
CVE-2016-4753

Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrar…

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Safari HIGH 8.8
CVE-2016-4728

WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote…

Fix: 10.0 / 12.5.1+
Fix from $1,950 2016-09-25
Iphone Os MEDIUM 5.9
CVE-2016-4722

The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attac…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Iphone Os HIGH 7.5
CVE-2016-4711

CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a …

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4706

cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors.

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 6.2
CVE-2016-4701

Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environme…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Iphone Os HIGH 7.8
CVE-2016-4698

AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance …

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X HIGH 7.3
CVE-2016-4641

Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain sensitive user information via…

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Iphone Os HIGH 7.8
CVE-2016-4594

The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows attackers to access…

Fix: 2.2.2 / 9.2.2+
Fix from $1,950 2016-07-22
Safari MEDIUM 5.4
CVE-2016-4590

WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a…

Fix: after 9.1.1
Fix from $1,600 2016-07-22
Mac Os X HIGH 7.5
CVE-2016-1843

The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via u…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 8.8
CVE-2016-1800

Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows user-assisted remote attackers to execute arbitra…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Iphone Os MEDIUM 5.5
CVE-2016-1752

The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to cause a denial of service via a …

Fix: 2.2 / 9.2+
Fix from $1,600 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1747

IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1746

IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru…

Fix: after 10.11.3
Fix from $1,950 2016-03-24