Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-09-25 | CVE-2016-4711 | Improper Input Validation vulnerability in Apple Iphone OS CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output. | 7.5 |
2016-09-25 | CVE-2016-4710 | Incorrect Type Conversion or Cast vulnerability in Apple mac OS X WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709. | 7.8 |
2016-09-25 | CVE-2016-4709 | Incorrect Type Conversion or Cast vulnerability in Apple mac OS X WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710. | 7.8 |
2016-09-25 | CVE-2016-4703 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X Bluetooth in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | 7.8 |
2016-09-25 | CVE-2016-4700 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4699. | 7.8 |
2016-09-25 | CVE-2016-4699 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4700. | 7.8 |
2016-09-25 | CVE-2016-4698 | Improper Input Validation vulnerability in Apple Iphone OS AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app. | 7.8 |
2016-09-25 | CVE-2016-4697 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | 7.8 |
2016-09-25 | CVE-2016-4696 | NULL Pointer Dereference vulnerability in Apple mac OS X AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app. | 7.8 |
2016-09-25 | CVE-2016-4611 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Tvos WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735. | 8.8 |