Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2019-01-11 CVE-2017-13888 Incorrect Type Conversion or Cast vulnerability in Apple Iphone OS
In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
network
low complexity
apple CWE-704
7.5
2019-01-11 CVE-2017-13887 Key Management Errors vulnerability in Apple mac OS X
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.
network
low complexity
apple CWE-320
7.5
2019-01-11 CVE-2017-13886 Unspecified vulnerability in Apple mac OS X
In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration.
network
low complexity
apple
6.5
2019-01-11 CVE-2016-7576 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
In iOS before 9.3.3, a memory corruption issue existed in the kernel.
local
low complexity
apple CWE-119
7.8
2019-01-11 CVE-2016-4644 Information Exposure vulnerability in Apple Iphone OS
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain.
network
low complexity
apple CWE-200
6.5
2019-01-11 CVE-2016-4643 Information Exposure vulnerability in Apple Iphone OS
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses.
network
low complexity
apple CWE-200
6.5
2019-01-11 CVE-2016-4642 7PK - Security Features vulnerability in Apple Iphone OS
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely.
network
high complexity
apple CWE-254
5.9
2018-12-07 CVE-2018-18313 Out-of-bounds Read vulnerability in multiple products
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
network
low complexity
perl canonical debian redhat netapp apple CWE-125
critical
9.1
2018-12-07 CVE-2018-18311 Integer Overflow or Wraparound vulnerability in multiple products
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
network
low complexity
perl canonical debian netapp redhat apple fedoraproject mcafee CWE-190
critical
9.8
2018-11-07 CVE-2018-16845 nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.
local
low complexity
f5 debian canonical opensuse apple
6.1