|
2511
|
5.5
4.9
|
MEDIUM
Local
|
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vecto…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-1865
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.3
|
2024-11-21 11:47
2016-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2512
|
7.8
7.2
|
HIGH
Local
|
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspe…
|
CWE-416
Use After Free
|
CVE-2016-1863
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.3
|
2024-11-21 11:47
2016-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2513
|
9.8
7.5
|
CRITICAL
Network
|
The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vecto…
|
NVD-CWE-Other
|
CVE-2015-7988
|
cpe:2.3:o:apple:iphone_os:*:*
|
9.0
|
|
|
9.1
|
2024-11-21 11:37
2016-06-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2514
|
9.8
6.8
|
CRITICAL
Network
|
Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueFor…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7987
|
cpe:2.3:o:apple:iphone_os:*:*
|
9.0
|
|
|
9.1
|
2024-11-21 11:37
2016-06-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2515
|
4.3
5.0
|
MEDIUM
Network
|
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a…
|
CWE-200
Information Exposure
|
CVE-2016-1864
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-06-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2516
|
7.5
5.0
|
HIGH
Network
|
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4447
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.2
|
|
|
2024-11-21 11:52
2016-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2517
|
9.8
10.0
|
CRITICAL
Network
|
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-4448
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.2
|
|
|
2024-11-21 11:52
2016-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2518
|
8.8
6.8
|
HIGH
Network
|
The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1859
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2519
|
6.5
4.3
|
MEDIUM
Network
|
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted …
|
CWE-200
Information Exposure
|
CVE-2016-1858
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2520
|
8.8
6.8
|
HIGH
Network
|
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1857
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|