Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.8
CVE-2016-7585
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It…
Mac Os X
after 10.12.3
MEDIUM 6.8
CVE-2016-4763
WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HT…
Safari
after 12.4.3
HIGH 7.5
CVE-2016-4754
ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mech…
Os X Server
after 5.1
MEDIUM 5.9
CVE-2016-1788
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which…
Iphone Os
after 10.11.3
HIGH 7.5
CVE-2016-1777
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection …
Mac Os X Server
after 5.0.15
MEDIUM 5.9
CVE-2016-1731
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying t…
Software Update
after 2.1.3.127
MEDIUM 6.8
CVE-2014-8840
The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirectio…
Iphone Os
after 8.1.2
MEDIUM 6.8
CVE-2014-4449
iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser…
Iphone Os
after 8.0.2
MEDIUM 5.4
CVE-2014-4428
Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by lever…
Mac Os X
after 10.9.5
MEDIUM 6.8
CVE-2014-4391
The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bundles, which allows remote att…
Mac Os X
after 10.9.4
HIGH 8.1
CVE-2014-4422
The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator during the early portion of the boot process, which…
Tvos
after 7.1.2
MEDIUM 5.6
CVE-2014-4364
The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to cal…
Iphone Os
after 7.1.2
MEDIUM 5.8
CVE-2014-1242
Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control ov…
Itunes
after 11.1.3
MEDIUM 5.0
CVE-2013-5182
Mail in Apple Mac OS X before 10.9 allows remote attackers to spoof the existence of a cryptographic signature for an e-mail message by using the mul…
Mac Os X
after 10.8.5
MEDIUM 6.4
CVE-2012-3732
Mail in Apple iOS before 6 uses an S/MIME message's From address as the displayed sender address, which allows remote attackers to spoof signed conte…
Iphone Os
after 5.1.1
MEDIUM 6.4
CVE-2012-0655
libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for re…
Mac Os X
after 10.7.3
MEDIUM 5.0
CVE-2011-0214
CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote w…
Safari
after 5.0.5
MEDIUM 5.0
CVE-2011-0207
The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows re…
Mac Os X
Patch available
MEDIUM 5.0
CVE-2010-3804EPSS 9%
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, us…
Safari
after 5.0.2
HIGH 9.3
CVE-2010-1377
Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attac…
Mac Os X
Patch available
MEDIUM 5.0
CVE-2010-1413
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in …
Safari
after 4.0.5
MEDIUM 5.0
CVE-2010-0525
Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certif…
Mac Os X
after 10.6.2
MEDIUM 5.0
CVE-2009-2843
Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers …
Mac Os X
Patch available
MEDIUM 5.4
CVE-2009-2808
Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-…
Mac Os X
after 10.6.1
HIGH 7.5
CVE-2009-3455
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field o…
Safari
after 4.0.2
HIGH 7.5
CVE-2009-3273
iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof…
Iphone Os
Mitigation only
MEDIUM 5.0
CVE-2009-1696
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in Jav…
Safari
after 4.0_beta
HIGH 7.5
CVE-2008-4227
Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level th…
Iphone Os
Mitigation only
MEDIUM 5.0
CVE-2008-4368
The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE…
Mac Os X
Mitigation only
HIGH 9.3
CVE-2007-5863EPSS 23%
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the clie…
Mac Os X
Mitigation only