Vulnerability index

Browse CVEs

358 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mac Os X MEDIUM 5.5
CVE-2016-7608

An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireFamily" component, which allow…

Fix: after 10.12.1
Fix from $1,600 2017-02-20
Icloud MEDIUM 5.5
CVE-2016-7614

An issue was discovered in certain Apple products. iCloud before 6.1 is affected. The issue involves the "Windows Security" component. It allows loca…

Fix: after 6.0.1
Fix from $1,600 2017-02-20
Safari MEDIUM 6.5
CVE-2016-7586

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTun…

Fix: after 12.5.3
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.9
CVE-2016-7579

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. The…

Fix: 10.0.1 / 10.1+
Fix from $1,600 2017-02-20
Iphone Os HIGH 7.1
CVE-2016-4660

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat…

Fix: after 10.12.0
Fix from $1,950 2017-02-20
Safari MEDIUM 6.5
CVE-2016-4613

An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affecte…

Fix: after 12.5.1
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.5
CVE-2016-4680

An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The i…

Fix: 3.1 / 10.0.1+
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.5
CVE-2016-4771

The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathna…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Safari MEDIUM 6.5
CVE-2016-4758

WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, whic…

Fix: after 12.4.3
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4755

Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4752

The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensi…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.3
CVE-2016-4745

The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes …

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4742

NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app.

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.3
CVE-2016-4713

CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Iphone Os HIGH 7.5
CVE-2016-4711

CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a …

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Iphone Os MEDIUM 6.5
CVE-2016-4708

CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attack…

Fix: 3.0 / 10.0+
Fix from $1,600 2016-09-25
Iphone Os MEDIUM 5.3
CVE-2016-4746

The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain se…

Fix: after 9.3.5
Fix from $1,600 2016-09-18
Watchos MEDIUM 5.5
CVE-2016-4719

The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attack…

Fix: after 9.3.5
Fix from $1,600 2016-09-18
Safari MEDIUM 5.3
CVE-2016-7152EPSS 14%

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for r…

Mitigation only
Fix from $1,600 2016-09-06
Mac Os X MEDIUM 5.5
CVE-2016-4648

Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bound…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Mac Os X MEDIUM 6.5
CVE-2016-4646

Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of servic…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Iphone Os MEDIUM 5.3
CVE-2016-4635

FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Iphone Os MEDIUM 5.5
CVE-2016-4628

IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause…

Fix: after 9.3.2
Fix from $1,600 2016-07-22
Safari MEDIUM 6.5
CVE-2016-1858

WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attack…

Fix: 2.12.0 / 9.1.1+
Fix from $1,600 2016-05-20
Mac Os X HIGH 7.5
CVE-2016-1853

Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Iphone Os MEDIUM 5.5
CVE-2016-1802

CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during k…

Fix: 2.2.1 / 9.2.1+
Fix from $1,600 2016-05-20
Mac Os X HIGH 7.5
CVE-2016-1801

The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, whi…

Fix: 9.2.1 / 9.3.2+
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.5
CVE-2016-1208

The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

Fix: after 14.0.3
Fix from $1,950 2016-05-14
Mac Os X Server MEDIUM 5.3
CVE-2016-1787

Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Safari MEDIUM 5.4
CVE-2016-1786

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status…

Fix: after 9.2.1
Fix from $1,600 2016-03-24