Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2020-02-05 CVE-2011-0220 Improper Input Validation vulnerability in Apple Bonjour
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
local
low complexity
apple CWE-20
4.9
2020-02-05 CVE-2019-15126 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
An issue was discovered on Broadcom Wi-Fi client devices.
2.9
2020-02-03 CVE-2016-4676 Information Exposure vulnerability in Apple mac OS X and Safari
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
network
low complexity
apple CWE-200
5.0
2020-01-30 CVE-2013-1867 Link Following vulnerability in Apple Tokend 032013
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
local
apple CWE-59
6.3
2020-01-30 CVE-2013-1866 Link Following vulnerability in Opensc Project Opensc
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
6.3
2020-01-09 CVE-2019-20372 HTTP Request Smuggling vulnerability in multiple products
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
4.3
2019-12-20 CVE-2012-6094 Incorrect Authorization vulnerability in multiple products
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
network
apple debian CWE-863
6.8
2019-12-19 CVE-2019-19906 Off-by-one Error vulnerability in multiple products
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet.
7.5
2019-12-18 CVE-2019-8849 Unspecified vulnerability in Apple Swiftnio SSL
The issue was addressed by signaling that an executable stack is not required.
network
low complexity
apple
7.5
2019-12-18 CVE-2019-8823 Out-of-bounds Write vulnerability in Apple products
Multiple memory corruption issues were addressed with improved memory handling.
network
apple CWE-787
6.8