Vulnerabilities > Apple > Low

DATE CVE VULNERABILITY TITLE RISK
2016-09-18 CVE-2016-4747 Information Exposure vulnerability in Apple Iphone OS
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.
network
high complexity
apple CWE-200
3.7
2016-09-18 CVE-2016-4749 Information Exposure vulnerability in Apple Iphone OS
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.
local
low complexity
apple CWE-200
3.3
2016-07-22 CVE-2016-4645 Information Exposure vulnerability in Apple mac OS X
CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
apple CWE-200
3.3
2016-07-22 CVE-2016-4583 Race Condition vulnerability in multiple products
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.
network
high complexity
apple webkitgtk CWE-362
3.1
2016-07-22 CVE-2016-4593 Information Exposure vulnerability in Apple Iphone OS
The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.
low complexity
apple CWE-200
2.4
2016-06-19 CVE-2016-1860 7PK - Security Features vulnerability in Apple mac OS X
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.
local
low complexity
apple CWE-254
3.3
2016-06-19 CVE-2016-1862 7PK - Security Features vulnerability in Apple mac OS X
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.
local
low complexity
apple CWE-254
3.3
2016-05-20 CVE-2016-1849 Information Exposure vulnerability in Apple Safari
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.
local
low complexity
apple CWE-200
3.3
2016-05-20 CVE-2016-1852 Information Exposure vulnerability in Apple Iphone OS
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.
low complexity
apple CWE-200
2.4
2016-05-20 CVE-2016-1790 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
local
low complexity
apple CWE-119
3.3