Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.8
CVE-2016-4697

Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memor…

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Iphone Os HIGH 7.8
CVE-2016-4698

AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance …

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X HIGH 7.8
CVE-2016-4696

AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL poin…

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X CRITICAL 9.1
CVE-2016-4694

The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applicati…

Fix: after 10.11.6
Fix from $2,300 2016-09-25
Iphone Os CRITICAL 9.8
CVE-2016-4658EPSS 9%

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does…

Fix: 2.9.5 / 3.0+
Fix from $2,300 2016-09-25
Safari MEDIUM 6.1
CVE-2016-4618

Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web…

Fix: after 9.3.5
Fix from $1,600 2016-09-25
Safari HIGH 8.8
CVE-2016-4611

WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (m…

Fix: 10.0+
Fix from $1,950 2016-09-25
Iphone Os MEDIUM 5.3
CVE-2016-4746

The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain se…

Fix: after 9.3.5
Fix from $1,600 2016-09-18
Iphone Os MEDIUM 5.9
CVE-2016-4741

The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS sess…

Fix: after 9.3.5
Fix from $1,600 2016-09-18
Watchos MEDIUM 5.5
CVE-2016-4719

The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attack…

Fix: after 9.3.5
Fix from $1,600 2016-09-18
Xcode HIGH 7.8
CVE-2016-4705

otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspec…

Fix: after 7.3.1
Fix from $1,950 2016-09-18
Xcode HIGH 7.8
CVE-2016-4704

otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspec…

Fix: after 7.3.1
Fix from $1,950 2016-09-18
Safari MEDIUM 5.3
CVE-2016-7152EPSS 14%

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for r…

Mitigation only
Fix from $1,600 2016-09-06
Iphone Os HIGH 8.8
CVE-2016-4657 KEVEPSS 64%

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web…

Fix: 9.3.5+
Fix from $1,950 2016-08-25
Iphone Os HIGH 7.8
CVE-2016-4656 KEVEPSS 21%

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrupti…

Fix: 9.3.5+
Fix from $1,950 2016-08-25
Iphone Os MEDIUM 5.5
CVE-2016-4655 KEVEPSS 30%

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

Fix: 9.3.5+
Fix from $1,600 2016-08-25
Iphone Os HIGH 7.8
CVE-2016-4654

IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory…

Mitigation only
Fix from $1,950 2016-08-18
Iphone Os HIGH 7.8
CVE-2016-4653

The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause…

Fix: 2.2.2 / 9.2.2+
Fix from $1,950 2016-07-22
Mac Os X MEDIUM 6.3
CVE-2016-4652

CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or …

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Safari MEDIUM 6.1
CVE-2016-4651

Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers …

Fix: after 9.3.2
Fix from $1,600 2016-07-22
Mac Os X MEDIUM 5.5
CVE-2016-4649

Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Mac Os X MEDIUM 5.5
CVE-2016-4648

Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bound…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Mac Os X HIGH 7.8
CVE-2016-4647

Audio in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted file.

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Mac Os X MEDIUM 6.5
CVE-2016-4646

Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of servic…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Mac Os X HIGH 7.3
CVE-2016-4641

Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain sensitive user information via…

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Mac Os X HIGH 7.8
CVE-2016-4640

Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context, obtain sensitive user information, or c…

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Mac Os X HIGH 7.0
CVE-2016-4639

Login Window in Apple OS X before 10.11.6 does not properly initialize memory, which allows local users to cause a denial of service via unspecified …

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Mac Os X HIGH 7.8
CVE-2016-4638

Login Window in Apple OS X before 10.11.6 allows attackers to gain privileges via a crafted app that leverages a "type confusion."

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Iphone Os HIGH 8.8
CVE-2016-4637

CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary…

Fix: 2.2.2 / 9.2.2+
Fix from $1,950 2016-07-22
Iphone Os MEDIUM 5.3
CVE-2016-4635

FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive…

Fix: after 10.11.5
Fix from $1,600 2016-07-22