Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-02-20 CVE-2016-4661 Improper Input Validation vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
network
apple CWE-20
4.3
2017-02-20 CVE-2016-4660 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
network
apple CWE-200
5.8
2017-02-20 CVE-2016-4617 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-264
4.6
2017-02-20 CVE-2016-4613 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
network
apple CWE-200
4.3
2017-01-11 CVE-2017-2947 Improper Input Validation vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF).
4.3
2016-12-29 CVE-2016-7080 NULL Pointer Dereference vulnerability in VMWare Tools
The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2016-7079.
local
low complexity
vmware apple CWE-476
4.6
2016-12-29 CVE-2016-7079 NULL Pointer Dereference vulnerability in VMWare Tools
The graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2016-7080.
local
low complexity
vmware apple CWE-476
4.6
2016-09-25 CVE-2016-4779 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
Apple Type Services (ATS) in Apple OS X before 10.12 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
network
apple CWE-119
6.8
2016-09-25 CVE-2016-4776 Out-of-bounds Read vulnerability in Apple products
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4774.
network
apple CWE-125
5.8
2016-09-25 CVE-2016-4774 Out-of-bounds Read vulnerability in Apple products
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4776.
network
apple CWE-125
5.8