Vulnerabilities > Apple > Iphone OS > 9.3.4

DATE CVE VULNERABILITY TITLE RISK
2016-09-18 CVE-2016-4740 Information Exposure vulnerability in Apple Iphone OS
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
local
apple CWE-200
1.9
2016-09-18 CVE-2016-4719 Information Exposure vulnerability in Apple Iphone OS and Watchos
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.
network
apple CWE-200
4.3
2016-09-18 CVE-2016-4620 Information Exposure vulnerability in Apple Iphone OS
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.
network
apple CWE-200
4.3
2016-08-25 CVE-2016-4657 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
network
apple CWE-119
6.8
2016-08-25 CVE-2016-4656 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
network
apple CWE-264
critical
9.3
2016-08-25 CVE-2016-4655 Information Exposure vulnerability in Apple Iphone OS
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
network
apple CWE-200
7.1
2016-07-23 CVE-2016-5131 Use After Free vulnerability in multiple products
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
8.8