Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-05-22 CVE-2017-2507 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-05-22 CVE-2017-2504 Cross-site Scripting vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-79
6.1
2017-05-22 CVE-2017-2502 Unspecified vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple
5.5
2017-05-22 CVE-2017-2500 Improper Input Validation vulnerability in Apple Safari
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
4.7
2017-05-22 CVE-2017-2497 Open Redirect vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-601
6.1
2017-05-22 CVE-2017-2495 Improper Input Validation vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
6.5
2017-04-24 CVE-2010-1776 7PK - Security Features vulnerability in Apple Iphone OS
Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to wipe the device.
network
high complexity
apple CWE-254
4.8
2017-04-07 CVE-2017-2387 Improper Certificate Validation vulnerability in Apple Music 1.2.1
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
high complexity
apple CWE-295
4.8
2017-04-05 CVE-2017-6975 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point.
low complexity
apple CWE-119
6.8
2017-04-02 CVE-2017-6974 Improper Input Validation vulnerability in Apple mac OS X 10.12.3
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-20
5.5