Vulnerabilities > Apple > Iphone OS > Low

DATE CVE VULNERABILITY TITLE RISK
2017-02-20 CVE-2017-2351 Improper Input Validation vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-20
2.1
2017-02-20 CVE-2017-2352 Security Bypass vulnerability in Apple Iphone OS and Watchos
An issue was discovered in certain Apple products.
local
low complexity
apple
2.1
2016-09-25 CVE-2016-4707 Information Exposure vulnerability in Apple Iphone OS and mac OS X
CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.
local
low complexity
apple CWE-200
2.1
2016-09-18 CVE-2016-4740 Information Exposure vulnerability in Apple Iphone OS
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
local
apple CWE-200
1.9
2016-09-18 CVE-2016-4749 Information Exposure vulnerability in Apple Iphone OS
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.
local
low complexity
apple CWE-200
2.1
2016-07-22 CVE-2016-4583 Race Condition vulnerability in multiple products
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.
network
high complexity
apple webkitgtk CWE-362
2.6
2016-07-22 CVE-2016-4593 Information Exposure vulnerability in Apple Iphone OS
The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.
local
low complexity
apple CWE-200
2.1
2016-07-22 CVE-2016-4635 Information Exposure vulnerability in Apple Iphone OS and mac OS X
FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive audio information in opportunistic circumstances, via unspecified vectors.
network
apple CWE-200
3.5
2016-05-20 CVE-2016-1849 Information Exposure vulnerability in Apple Iphone OS and Safari
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.
local
low complexity
apple CWE-200
2.1
2016-05-20 CVE-2016-1852 Information Exposure vulnerability in Apple Iphone OS
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.
local
low complexity
apple CWE-200
2.1