Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-27 CVE-2020-3841 Insufficiently Protected Credentials vulnerability in Apple Iphone OS
The issue was addressed with improved UI handling.
network
low complexity
apple CWE-522
6.5
2020-02-27 CVE-2020-3839 Improper Input Validation vulnerability in Apple mac OS X
A validation issue was addressed with improved input sanitization.
local
low complexity
apple CWE-20
5.5
2020-02-27 CVE-2020-3836 Unspecified vulnerability in Apple products
An access issue was addressed with improved memory management.
local
low complexity
apple
5.5
2020-02-27 CVE-2020-3835 Link Following vulnerability in Apple mac OS X
A validation issue existed in the handling of symlinks.
local
low complexity
apple CWE-59
4.4
2020-02-27 CVE-2020-3833 Unspecified vulnerability in Apple Safari
An inconsistent user interface issue was addressed with improved state management.
network
low complexity
apple
4.3
2020-02-05 CVE-2011-0220 Improper Input Validation vulnerability in Apple Bonjour
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
local
low complexity
apple CWE-20
5.5
2020-01-30 CVE-2013-1867 Link Following vulnerability in Apple Tokend 032013
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
low complexity
apple CWE-59
6.1
2020-01-09 CVE-2019-20372 HTTP Request Smuggling vulnerability in multiple products
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
network
low complexity
f5 apple canonical opensuse netapp CWE-444
5.3
2019-12-18 CVE-2019-8817 Improper Input Validation vulnerability in Apple mac OS X
A validation issue was addressed with improved input sanitization.
local
low complexity
apple CWE-20
5.5
2019-12-18 CVE-2019-8813 Cross-site Scripting vulnerability in multiple products
A logic issue was addressed with improved state management.
network
low complexity
apple webkitgtk CWE-79
6.1