Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-24 CVE-2010-1776 7PK - Security Features vulnerability in Apple Iphone OS
Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to wipe the device.
network
high complexity
apple CWE-254
4.8
2017-04-07 CVE-2017-2387 Improper Certificate Validation vulnerability in Apple Music 1.2.1
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
high complexity
apple CWE-295
4.8
2017-04-05 CVE-2017-6975 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point.
low complexity
apple CWE-119
6.8
2017-04-02 CVE-2017-6974 Improper Input Validation vulnerability in Apple mac OS X 10.12.3
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-20
5.5
2017-04-02 CVE-2017-2489 Information Exposure vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-04-02 CVE-2017-2486 Forced Browsing vulnerability in Apple Safari
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-425
6.5
2017-04-02 CVE-2017-2480 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-200
6.5
2017-04-02 CVE-2017-2479 Improper Input Validation vulnerability in Apple products
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
6.5
2017-04-02 CVE-2017-2475 Cross-site Scripting vulnerability in Apple Safari
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-79
6.1
2017-04-02 CVE-2017-2453 Improper Input Validation vulnerability in Apple Safari
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
6.5