Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-27 CVE-2020-3862 A denial of service issue was addressed with improved memory handling.
network
apple opensuse
4.3
2020-02-27 CVE-2020-3846 XML Injection (aka Blind XPath Injection) vulnerability in Apple products
A buffer overflow was addressed with improved size validation.
network
apple CWE-91
6.8
2020-02-27 CVE-2020-3841 Insufficiently Protected Credentials vulnerability in Apple Safari
The issue was addressed with improved UI handling.
network
apple CWE-522
4.3
2020-02-27 CVE-2020-3840 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An off by one issue existed in the handling of racoon configuration files.
network
apple CWE-119
6.8
2020-02-27 CVE-2020-3833 Unspecified vulnerability in Apple Safari
An inconsistent user interface issue was addressed with improved state management.
network
apple
4.3
2020-02-27 CVE-2020-3826 Out-of-bounds Read vulnerability in Apple products
An out-of-bounds read was addressed with improved input validation.
network
apple CWE-125
6.8
2020-02-27 CVE-2020-3825 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
Multiple memory corruption issues were addressed with improved memory handling.
network
apple CWE-119
6.8
2020-02-12 CVE-2014-8128 Out-of-bounds Write vulnerability in Libtiff
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
4.3
2020-02-05 CVE-2011-0220 Improper Input Validation vulnerability in Apple Bonjour
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
local
low complexity
apple CWE-20
4.9
2020-02-03 CVE-2016-4676 Information Exposure vulnerability in Apple mac OS X and Safari
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
network
low complexity
apple CWE-200
5.0