|
2561
|
6.5
4.3
|
MEDIUM
Network
|
The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-1784
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2562
|
8.8
9.3
|
HIGH
Network
|
WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1783
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2563
|
6.5
4.3
|
MEDIUM
Network
|
WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a craf…
|
CWE-284
Improper Access Control
|
CVE-2016-1782
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2564
|
4.3
4.3
|
MEDIUM
Network
|
WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.
|
CWE-19
Data Processing Errors
|
CVE-2016-1781
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2565
|
4.3
4.3
|
MEDIUM
Network
|
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical envi…
|
CWE-200
Information Exposure
|
CVE-2016-1780
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2566
|
6.5
4.3
|
MEDIUM
Network
|
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request.
|
CWE-200
Information Exposure
|
CVE-2016-1779
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2567
|
8.8
9.3
|
HIGH
Network
|
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
|
CWE-399
Resource Management Errors
|
CVE-2016-1778
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2568
|
7.8
9.3
|
HIGH
Local
|
TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1775
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
9.3
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2569
|
7.5
5.0
|
HIGH
Network
|
The Profiles component in Apple iOS before 9.3 does not properly validate certificates, which allows attackers to spoof an MDM profile trust relationship via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2016-1766
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2570
|
3.5
3.5
|
LOW
Network
|
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing …
|
CWE-20
Improper Input Validation
|
CVE-2016-1763
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:47
2016-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|