Vulnerabilities > Apple > High

DATE CVE VULNERABILITY TITLE RISK
2016-09-25 CVE-2016-4709 Incorrect Type Conversion or Cast vulnerability in Apple mac OS X
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710.
local
low complexity
apple CWE-704
7.2
2016-09-25 CVE-2016-4694 Improper Access Control vulnerability in Apple mac OS X and OS X Server
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue, a related issue to CVE-2016-5387.
network
low complexity
apple CWE-284
7.5
2016-09-18 CVE-2016-4705 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Xcode
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4704.
local
low complexity
apple CWE-119
7.2
2016-09-18 CVE-2016-4704 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Xcode
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4705.
local
low complexity
apple CWE-119
7.2
2016-08-25 CVE-2016-4655 Information Exposure vulnerability in Apple Iphone OS
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
network
apple CWE-200
7.1
2016-07-23 CVE-2016-5131 Use After Free vulnerability in multiple products
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
8.8
2016-07-22 CVE-2016-4653 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4582.
local
low complexity
apple CWE-119
7.2
2016-07-22 CVE-2016-4647 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
Audio in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted file.
local
low complexity
apple CWE-119
7.2
2016-07-22 CVE-2016-4634 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
The Graphics Drivers subsystem in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
local
low complexity
apple CWE-119
7.2
2016-07-22 CVE-2016-4627 NULL Pointer Dereference vulnerability in Apple Iphone OS, Tvos and Watchos
IOAcceleratorFamily in Apple iOS before 9.3.3, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
local
low complexity
apple CWE-476
7.2