|
267191
|
5.3 |
MEDIUM
Network
|
apple
|
mac_os_x_server
|
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP …
|
CWE-284
Improper Access Control
|
CVE-2016-1776
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267192
|
7.8 |
HIGH
Local
|
apple
|
watchos iphone_os mac_os_x tvos
|
TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1775
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267193
|
5.3 |
MEDIUM
Network
|
apple
|
mac_os_x_server
|
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitiv…
|
CWE-284
Improper Access Control
|
CVE-2016-1774
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267194
|
3.3 |
LOW
Local
|
apple
|
mac_os_x
|
The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1773
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267195
|
4.3 |
MEDIUM
Network
|
apple
|
safari
|
The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-1772
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267196
|
6.5 |
MEDIUM
Network
|
apple
|
safari
|
The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.
|
CWE-19
Data Processing Errors
|
CVE-2016-1771
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267197
|
6.5 |
MEDIUM
Network
|
apple
|
mac_os_x
|
The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing action via a tel: URL.
|
CWE-284
Improper Access Control
|
CVE-2016-1770
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267198
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Photoshop file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1769
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267199
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1768
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267200
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1767
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|