Vulnerability index

Browse CVEs

365 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-4296 This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks. Mac Os X Mitigation only Fix from $2,3002020-10-27 HIGH 8.8 CVE-2019-8792 An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. … Shazam Mitigation only Fix from $1,9502019-12-18 MEDIUM 6.8 CVE-2019-9536 Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical acc… Iphone 3gs No fix yet Fix from $1,6002019-11-22 MEDIUM 5.9 CVE-2017-17688EPSS 6% The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAI… Mail No fix yet Fix from $1,6002018-05-16 HIGH 7.8 CVE-2017-13827 An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "kext tools" component. It allows attackers… Mac Os X Mitigation only Fix from $1,9502018-04-03 HIGH 7.5 CVE-2017-13837 An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Installer" component. It does not properly… Mac Os X Mitigation only Fix from $1,9502018-04-03 MEDIUM 5.5 CVE-2017-13839 An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" component. It allows local user… Mac Os X Mitigation only Fix from $1,6002018-04-03 MEDIUM 5.5 CVE-2017-13851 An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "DesktopServices" component. It allows loca… Mac Os X Mitigation only Fix from $1,6002018-04-03 CRITICAL 9.8 CVE-2017-17821 WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buff… Safari Mitigation only Fix from $2,3002017-12-21 HIGH 7.5 CVE-2017-14315 In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a t… Iphone Os Mitigation only Fix from $1,9502017-09-12 HIGH 8.8 CVE-2011-3438 WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution. Safari Mitigation only Fix from $1,9502017-04-24 HIGH 7.8 CVE-2010-1816 Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary… Mac Os X Mitigation only Fix from $1,9502017-04-13 HIGH 7.8 CVE-2010-1821 Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges. Mac Os X Mitigation only Fix from $1,9502017-04-13 CRITICAL 9.8 CVE-2017-5949 JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based ou… Safari Mitigation only Fix from $2,3002017-04-03 HIGH 7.5 CVE-2016-10222 runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial… Safari Mitigation only Fix from $1,9502017-04-03 HIGH 7.5 CVE-2016-10226 JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-… Safari Mitigation only Fix from $1,9502017-04-03 MEDIUM 5.5 CVE-2017-6974 An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the "Sys… Mac Os X Mitigation only Fix from $1,6002017-04-02 HIGH 8.8 CVE-2017-2471EPSS 9% An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS before 3.2 is affected. The i… Safari No fix yet Fix from $1,9502017-04-02 MEDIUM 5.3 CVE-2016-7152EPSS 14% The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for r… Safari Mitigation only Fix from $1,6002016-09-06 HIGH 7.8 CVE-2016-4654 IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory… Iphone Os Mitigation only Fix from $1,9502016-08-18 MEDIUM 5.4 CVE-2016-4604 Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP por… Safari Mitigation only Fix from $1,6002016-07-22 HIGH 7.5 CVE-2016-4591 WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to acces… Webkit No fix yet Fix from $1,9502016-07-22 HIGH 8.8 CVE-2016-4589 WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of s… Webkit No fix yet Fix from $1,9502016-07-22 HIGH 8.8 CVE-2016-4588 WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted we… Webkit No fix yet Fix from $1,9502016-07-22 MEDIUM 6.5 CVE-2016-4587 WebKit in Apple iOS before 9.3.3 and tvOS before 9.2.2 allows remote attackers to obtain sensitive information from uninitialized process memory via … Webkit No fix yet Fix from $1,6002016-07-22 MEDIUM 6.1 CVE-2016-4585 Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.… Webkit No fix yet Fix from $1,6002016-07-22 HIGH 9.3 CVE-2014-8835EPSS 8% The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type,… Mac Os X No fix yet Fix from $1,9502015-01-30 HIGH 9.3 CVE-2014-7861 The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code… Mac Os X Mitigation only Fix from $1,9502014-10-05 MEDIUM 6.9 CVE-2014-4416 An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls… Mac Os X Mitigation only Fix from $1,6002014-09-19 HIGH 10.0 CVE-2014-4376 IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of serv… Mac Os X Mitigation only Fix from $1,9502014-09-19