Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-05-20 CVE-2016-1798 Multiple Security vulnerability in Apple Mac OS X APPLE-SA-2016-05-16-4
Audio in Apple OS X before 10.11.5 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
network
apple
4.3
2016-05-20 CVE-2016-1796 Information Exposure vulnerability in Apple mac OS X
Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app.
network
apple CWE-200
4.3
2016-05-20 CVE-2016-1791 Information Exposure vulnerability in Apple mac OS X
The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
network
apple CWE-200
4.3
2016-05-20 CVE-2016-1790 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
network
apple CWE-119
4.3
2016-05-14 CVE-2016-1208 Information Exposure vulnerability in multiple products
The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.
network
low complexity
apple filemaker CWE-200
5.0
2016-05-11 CVE-2016-1092 Information Exposure vulnerability in Adobe products
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information from process memory via unspecified vectors, a different vulnerability than CVE-2016-1079.
network
low complexity
apple microsoft adobe CWE-200
5.0
2016-05-11 CVE-2016-1079 Information Exposure vulnerability in Adobe products
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information from process memory via unspecified vectors, a different vulnerability than CVE-2016-1092.
network
low complexity
apple microsoft adobe CWE-200
5.0
2016-04-30 CVE-2016-1111 Double Free Remote Code Execution vulnerability in Adobe Acrobat and Reader
Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via a crafted Graphics State dictionary.
6.8
2016-04-05 CVE-2016-1789 XML External Entity Information Disclosure vulnerability in Apple Ibooks Author 2.4.0
Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
apple
4.3
2016-03-24 CVE-2016-1787 Information Exposure vulnerability in Apple mac OS X Server
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
network
low complexity
apple CWE-200
5.0