Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-7284 Unspecified vulnerability in Apple Iphone OS
This issue was addressed with improved checks.
network
apple
4.3
2019-12-18 CVE-2019-6239 Unspecified vulnerability in Apple mac OS X
This issue was addressed with improved handling of file metadata.
local
low complexity
apple
4.6
2019-12-18 CVE-2019-6237 Out-of-bounds Write vulnerability in Apple products
Multiple memory corruption issues were addressed with improved memory handling.
network
apple CWE-787
6.8
2019-12-18 CVE-2019-6222 Unspecified vulnerability in Apple Iphone OS
A consistency issue was addressed with improved state handling.
network
apple
4.3
2019-12-18 CVE-2019-6204 Cross-site Scripting vulnerability in Apple Safari
A logic issue was addressed with improved validation.
network
apple CWE-79
4.3
2019-11-22 CVE-2019-9536 Improper Privilege Management vulnerability in Apple Iphone 3GS
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'.
local
apple CWE-269
6.9
2019-10-03 CVE-2019-15165 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
5.3
2019-08-16 CVE-2019-7957 Unspecified vulnerability in Adobe Creative Cloud
Creative Cloud Desktop Application versions 4.6.1 and earlier have a security bypass vulnerability.
network
low complexity
adobe apple microsoft
5.0
2019-08-14 CVE-2019-9506 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation.
4.8
2019-08-13 CVE-2019-9516 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service.
6.5