|
2251
|
7.8
6.8
|
HIGH
Local
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. The issue involves the "CoreAudio" component. It al…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7008
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
10.3.2
|
|
|
2024-11-21 12:30
2017-07-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2252
|
7.5
5.0
|
HIGH
Network
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "EventKitUI" component. It allows remote attackers to cause a denial of service (resource cons…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-7007
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
10.3.2
|
|
|
2024-11-21 12:30
2017-07-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2253
|
5.3
2.6
|
MEDIUM
Network
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allow…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-7006
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
10.3.3
|
2024-11-21 12:30
2017-07-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2254
|
6.5
4.3
|
MEDIUM
Network
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
|
CWE-20
Improper Input Validation
|
CVE-2017-2517
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
10.3.2
|
|
|
2024-11-21 12:23
2017-07-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2255
|
8.1
6.8
|
HIGH
Network
|
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-11103
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
11.0
|
2024-11-21 12:07
2017-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2256
|
8.8
6.8
|
HIGH
Network
|
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitrary code via a crafted web page, or a crafted file.
|
CWE-416
Use After Free
|
CVE-2017-2491
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
10.2.1
|
|
|
2024-11-21 12:23
2017-06-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2257
|
8.8
6.8
|
HIGH
Network
|
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
|
NVD-CWE-noinfo
|
CVE-2016-9840
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
11
|
2024-11-21 12:01
2017-05-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2258
|
9.8
7.5
|
CRITICAL
Network
|
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
|
NVD-CWE-noinfo
|
CVE-2016-9843
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
11
|
2024-11-21 12:01
2017-05-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2259
|
8.8
6.8
|
HIGH
Network
|
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
|
NVD-CWE-noinfo
|
CVE-2016-9842
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
11
|
2024-11-21 12:01
2017-05-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2260
|
9.8
7.5
|
CRITICAL
Network
|
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
|
NVD-CWE-noinfo
|
CVE-2016-9841
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
11
|
2024-11-21 12:01
2017-05-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|