Vulnerabilities > Apple > Tvos > Low

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-8704 Improper Authentication vulnerability in Apple Iphone OS
An authentication issue was addressed with improved state management.
local
low complexity
apple CWE-287
2.1
2019-12-18 CVE-2019-8798 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
A memory corruption issue was addressed with improved memory handling.
local
low complexity
apple CWE-119
2.1
2019-04-03 CVE-2018-4305 Improper Input Validation vulnerability in Apple Iphone OS, Tvos and Watchos
An input validation issue was addressed with improved input validation.
low complexity
apple CWE-20
3.3
2019-04-03 CVE-2018-4313 Improper Input Validation vulnerability in Apple Iphone OS, Tvos and Watchos
A consistency issue existed in the handling of application snapshots.
local
low complexity
apple CWE-20
2.1
2019-04-03 CVE-2018-4395 Improper Input Validation vulnerability in Apple products
This issue was addressed with improved checks.
local
low complexity
apple CWE-20
2.1
2019-02-18 CVE-2019-8906 Out-of-bounds Read vulnerability in multiple products
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
3.6
2018-04-03 CVE-2017-7066 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS and Tvos
An issue was discovered in certain Apple products.
low complexity
apple CWE-119
3.3
2017-07-20 CVE-2017-7006 Information Exposure Through Discrepancy vulnerability in Apple products
An issue was discovered in certain Apple products.
network
high complexity
apple CWE-203
2.6
2017-04-02 CVE-2017-2390 Link Following vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-59
2.1
2016-07-22 CVE-2016-4583 Race Condition vulnerability in multiple products
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.
network
high complexity
apple webkitgtk CWE-362
2.6