|
2541
|
7.8
9.3
|
HIGH
Local
|
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrar…
|
CWE-20
Improper Input Validation
|
CVE-2016-4698
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2542
|
9.8
10.0
|
CRITICAL
Network
|
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, wh…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4658
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
10.0
|
2024-11-21 11:52
2016-09-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2543
|
6.1
4.3
|
MEDIUM
Network
|
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Unive…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4618
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2544
|
8.8
6.8
|
HIGH
Network
|
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a differ…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4611
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
10.0
|
2024-11-21 11:52
2016-09-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2545
|
3.3
2.1
|
LOW
Local
|
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.
|
CWE-200
Information Exposure
|
CVE-2016-4749
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2546
|
3.7
4.3
|
LOW
Network
|
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-4747
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2547
|
5.3
5.0
|
MEDIUM
Network
|
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances…
|
CWE-200
Information Exposure
|
CVE-2016-4746
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2548
|
5.9
4.3
|
MEDIUM
Network
|
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
|
CWE-254
7PK - Security Features
|
CVE-2016-4741
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2549
|
2.9
1.9
|
LOW
Local
|
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via…
|
CWE-200
Information Exposure
|
CVE-2016-4740
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2550
|
5.5
4.3
|
MEDIUM
Local
|
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted a…
|
CWE-200
Information Exposure
|
CVE-2016-4719
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|