|
2551
|
7.8
9.3
|
HIGH
Local
|
The Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a den…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1808
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2552
|
5.1
1.9
|
MEDIUM
Local
|
Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to obtain sensitive information from kernel …
|
CWE-362
Race Condition
|
CVE-2016-1807
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2553
|
7.8
6.8
|
HIGH
Local
|
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-1803
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2554
|
5.5
4.3
|
MEDIUM
Local
|
CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to …
|
CWE-200
Information Exposure
|
CVE-2016-1802
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2555
|
7.5
5.0
|
HIGH
Network
|
The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive inf…
|
CWE-200
Information Exposure
|
CVE-2016-1801
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3.2
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2556
|
3.3
4.3
|
LOW
Local
|
Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1790
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.3.1
|
|
|
2024-11-21 11:47
2016-05-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2557
|
6.2
2.1
|
MEDIUM
Local
|
The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app.
|
CWE-284
Improper Access Control
|
CVE-2016-1760
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2558
|
5.9
2.6
|
MEDIUM
Network
|
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachmen…
|
CWE-310
Cryptographic Issues
|
CVE-2016-1788
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2559
|
5.4
5.8
|
MEDIUM
Network
|
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the …
|
CWE-200
Information Exposure
|
CVE-2016-1786
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2560
|
6.5
4.3
|
MEDIUM
Network
|
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Or…
|
CWE-200
Information Exposure
|
CVE-2016-1785
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|