Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-05-20 CVE-2016-1803 NULL Pointer Dereference vulnerability in Apple products
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
network
apple CWE-476
6.8
2016-05-20 CVE-2016-1802 Information Exposure vulnerability in Apple products
CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive information via a crafted app.
network
apple CWE-200
4.3
2016-05-20 CVE-2016-1801 Information Exposure vulnerability in Apple Iphone OS, mac OS X and Tvos
The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
apple CWE-200
5.0
2016-05-20 CVE-2016-1798 Multiple Security vulnerability in Apple Mac OS X APPLE-SA-2016-05-16-4
Audio in Apple OS X before 10.11.5 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
network
apple
4.3
2016-05-20 CVE-2016-1796 Information Exposure vulnerability in Apple mac OS X
Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app.
network
apple CWE-200
4.3
2016-05-20 CVE-2016-1791 Information Exposure vulnerability in Apple mac OS X
The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
network
apple CWE-200
4.3
2016-05-20 CVE-2016-1790 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
network
apple CWE-119
4.3
2016-05-18 CVE-2016-0731 Improper Access Control vulnerability in Apache Ambari
The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.
network
low complexity
apache CWE-284
4.0
2016-05-17 CVE-2016-4425 Improper Input Validation vulnerability in Jansson Project Jansson
Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.
network
low complexity
jansson-project CWE-20
5.0
2016-05-17 CVE-2016-3727 Information Exposure vulnerability in Jenkins
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
network
low complexity
jenkins redhat CWE-200
4.0