|
266051
|
5.5 |
MEDIUM
Local
|
apple
|
ibooks_author
|
Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, relat…
|
NVD-CWE-Other
|
CVE-2016-1789
|
2024-11-21 11:47 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266052
|
6.2 |
MEDIUM
Local
|
apple
|
iphone_os
|
The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app.
|
CWE-284
Improper Access Control
|
CVE-2016-1760
|
2024-11-21 11:47 |
2016-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266053
|
5.9 |
MEDIUM
Network
|
apple
|
watchos iphone_os mac_os_x
|
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachmen…
|
CWE-310
Cryptographic Issues
|
CVE-2016-1788
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266054
|
5.3 |
MEDIUM
Network
|
apple
|
mac_os_x_server
|
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-1787
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266055
|
5.4 |
MEDIUM
Network
|
apple
|
iphone_os safari
|
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the …
|
CWE-200
Information Exposure
|
CVE-2016-1786
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266056
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os safari
|
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Or…
|
CWE-200
Information Exposure
|
CVE-2016-1785
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266057
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os tvos safari
|
The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-1784
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266058
|
8.8 |
HIGH
Network
|
apple webkitgtk
|
iphone_os tvos safari webkitgtk\+
|
WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1783
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266059
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os safari
|
WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a craf…
|
CWE-284
Improper Access Control
|
CVE-2016-1782
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266060
|
4.3 |
MEDIUM
Network
|
apple
|
iphone_os safari
|
WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.
|
CWE-19
Data Processing Errors
|
CVE-2016-1781
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|