Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.5
CVE-2016-1801

The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, whi…

Fix: 9.2.1 / 9.3.2+
Fix from $1,950 2016-05-20
Mac Os X HIGH 8.8
CVE-2016-1800

Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows user-assisted remote attackers to execute arbitra…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1799

Audio in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1797

Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbi…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1795

AppleGraphicsPowerManagement in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of ser…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1794

The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to execute arbitrary code…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1793

AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1792

The AMD subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memor…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Itunes HIGH 7.8
CVE-2016-1742

Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the …

Fix: after 12.3.1
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.5
CVE-2016-1208

The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

Fix: after 14.0.3
Fix from $1,950 2016-05-14
Ibooks Author MEDIUM 5.5
CVE-2016-1789

Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declarat…

Fix: after 2.4.0
Fix from $1,600 2016-04-05
Iphone Os MEDIUM 6.2
CVE-2016-1760

The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary…

Fix: after 9.2.1
Fix from $1,600 2016-03-29
Iphone Os MEDIUM 5.9
CVE-2016-1788

Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which…

Fix: after 10.11.3
Fix from $1,600 2016-03-24
Mac Os X Server MEDIUM 5.3
CVE-2016-1787

Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Safari MEDIUM 5.4
CVE-2016-1786

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1785

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, w…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1784

The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of ser…

Fix: 9.1 / 9.2+
Fix from $1,600 2016-03-24
Safari HIGH 8.8
CVE-2016-1783

WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service…

Fix: 2.10.5 / 9.1+
Fix from $1,950 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1782

WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attacke…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1779

WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Safari HIGH 8.8
CVE-2016-1778

WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio…

Fix: after 9.2.1
Fix from $1,950 2016-03-24
Mac Os X Server HIGH 7.5
CVE-2016-1777

Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection …

Fix: after 5.0.15
Fix from $1,950 2016-03-24
Mac Os X Server MEDIUM 5.3
CVE-2016-1776

Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtai…

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Iphone Os HIGH 7.8
CVE-2016-1775

TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary cod…

Fix: 2.2 / 9.2+
Fix from $1,950 2016-03-24
Mac Os X Server MEDIUM 5.3
CVE-2016-1774

The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes…

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1771

The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted …

Fix: after 9.0.3
Fix from $1,600 2016-03-24
Mac Os X MEDIUM 6.5
CVE-2016-1770

The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing actio…

Fix: after 10.11.3
Fix from $1,600 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1769EPSS 5%

QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1768EPSS 17%

QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1767EPSS 5%

QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Fix: after 10.11.3
Fix from $1,950 2016-03-24