|
2481
|
5.5
4.3
|
MEDIUM
Local
|
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted a…
|
CWE-200
Information Exposure
|
CVE-2016-4719
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2482
|
3.3
4.3
|
LOW
Local
|
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via…
|
CWE-200
Information Exposure
|
CVE-2016-4620
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.5
|
|
|
2024-11-21 11:52
2016-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2483
|
8.8
6.8
|
HIGH
Network
|
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
|
CWE-787
Out-of-bounds Write
|
CVE-2016-4657
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.5
|
2026-04-22 01:22
2016-08-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2484
|
7.8
9.3
|
HIGH
Local
|
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
|
CWE-787
Out-of-bounds Write
|
CVE-2016-4656
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.5
|
2026-04-22 01:22
2016-08-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2485
|
5.5
7.1
|
MEDIUM
Local
|
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
|
NVD-CWE-noinfo
|
CVE-2016-4655
|
cpe:2.3:o:apple:iphone_os:10.0:* cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.5
|
2026-04-22 01:23
2016-08-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2486
|
7.8
9.3
|
HIGH
Local
|
IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
|
CWE-264 CWE-119
Permissions, Privileges, and Access Controls Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4654
|
cpe:2.3:o:apple:iphone_os:9.3.3:*
|
|
|
|
|
2024-11-21 11:52
2016-08-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2487
|
8.8
6.8
|
HIGH
Network
|
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via…
|
CWE-416
Use After Free
|
CVE-2016-5131
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
10.0
|
2024-11-21 11:53
2016-07-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2488
|
7.8
7.2
|
HIGH
Local
|
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4653
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.3
|
2024-11-21 11:52
2016-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2489
|
6.1
4.3
|
MEDIUM
Network
|
Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers to inject arbitrary web script or HTML via a craft…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4651
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.2
|
|
|
2024-11-21 11:52
2016-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2490
|
8.8
6.8
|
HIGH
Network
|
CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupt…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4637
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.3
|
2024-11-21 11:52
2016-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|