|
265041
|
6.2 |
MEDIUM
Local
|
apple
|
mac_os_x
|
Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable.
|
CWE-20
Improper Input Validation
|
CVE-2016-4701
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265042
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4700
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265043
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4699
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265044
|
7.8 |
HIGH
Local
|
apple
|
iphone_os mac_os_x
|
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrar…
|
CWE-20
Improper Input Validation
|
CVE-2016-4698
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265045
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4697
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265046
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-4696
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265047
|
9.1 |
CRITICAL
Network
|
apple
|
mac_os_x os_x_server
|
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data…
|
CWE-284
Improper Access Control
|
CVE-2016-4694
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265048
|
9.8 |
CRITICAL
Network
|
apple xmlsoft
|
watchos tvos iphone_os mac_os_x libxml2
|
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, wh…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4658
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265049
|
6.1 |
MEDIUM
Network
|
apple
|
safari iphone_os
|
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Unive…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4618
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265050
|
8.8 |
HIGH
Network
|
apple
|
tvos iphone_os safari
|
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a differ…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4611
|
2024-11-21 11:52 |
2016-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|