CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-2464

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2469

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2470

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    9.8
    Critical

    CVE-2017-2477

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "libxslt" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 2 Apr 2017
    7.5
    High

    CVE-2017-2484

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Phone" component. It allows attackers to trigger telephone calls to arbitrary numbers via a third-party app.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2490

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2485

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Security" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted X.509 certificate file.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2378

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves bookmark creation in the "WebKit" component. It allows remote attackers to execute arbitrary code or spoof a bookmark by leveraging mishandling of links during drag-and-drop actions.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2379

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Carbon" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted .dfont file.

    Published: 2 Apr 2017
    5.5
    Medium

    CVE-2017-2385

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.

    Published: 2 Apr 2017
    6.1
    Medium

    CVE-2017-2393

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Safari Reader" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site.

    Published: 2 Apr 2017
    5.3
    Medium

    CVE-2017-2400

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "SafariViewController" component. It allows attackers to obtain sensitive information by leveraging the SafariViewController's incorrect synchronization of Safari cache clearing.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2407

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file.

    Published: 2 Apr 2017
    5.3
    Medium

    CVE-2017-2414

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "DataAccess" component. It allows remote attackers to access Exchange traffic in opportunistic circumstances by leveraging a mistake in typing an e-mail address.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2421

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "AppleGraphicsPowerManagement" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    9.8
    Critical

    CVE-2017-2428

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves nghttp2 before 1.17.0 in the "HTTPProtocol" component. It allows remote HTTP/2 servers to have an unspecified impact via unknown vectors.

    Published: 2 Apr 2017
    6.5
    Medium

    CVE-2017-2442

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 2 Apr 2017
    7
    High

    CVE-2017-2456

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2463

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2476

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    6.5
    Medium

    CVE-2017-2479

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2483

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    6.5
    Medium

    CVE-2017-2486

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2487

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file.

    Published: 2 Apr 2017
    6.8
    Medium

    CVE-2016-7585

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.

    Published: 2 Apr 2017
    7.5
    High

    CVE-2017-2376

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar by leveraging text input during the loading of a page.

    Published: 2 Apr 2017
    7.5
    High

    CVE-2017-2377

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows attackers to cause a denial of service (memory corruption and application crash) by leveraging a window-close action during a debugger-pause state.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2381

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "sudo" component. It allows remote authenticated users to gain privileges by leveraging membership in the admin group on a network directory server.

    Published: 2 Apr 2017
    7.5
    High

    CVE-2017-2382

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS Server before 5.3 is affected. The issue involves the "Wiki Server" component. It allows remote attackers to enumerate user accounts via unspecified vectors.

    Published: 2 Apr 2017
    3.1
    Low

    CVE-2017-2383

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. The issue involves cleartext client-certificate transmission in the "APNs Server" component. It allows man-in-the-middle attackers to track users via correlation with this certificate.

    Published: 2 Apr 2017
    3.3
    Low

    CVE-2017-2384

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves mishandling of deletion within the SQLite subsystem of the "Safari" component. It allows local users to identify the web-site visits that occurred in Private Browsing mode.

    Published: 2 Apr 2017
    5.5
    Medium

    CVE-2017-2388

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 2 Apr 2017
    8.1
    High

    CVE-2017-2389

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof an HTTP authentication sheet or cause a denial of service via a crafted web site.

    Published: 2 Apr 2017
    5.3
    Medium

    CVE-2017-2391

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2392

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2395

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2396

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    2.4
    Low

    CVE-2017-2397

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Accounts" component. It allows physically proximate attackers to discover an Apple ID by reading an iCloud authentication prompt on the lock screen.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2398

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 2 Apr 2017
    4.6
    Medium

    CVE-2017-2399

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an encryption key derived only from the hardware UID (rather than that UID in addition to the user passcode).

    Published: 2 Apr 2017
    9.8
    Critical

    CVE-2017-2402

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of profile uninstall actions in the "MCX Client" component when a profile has multiple payloads. It allows remote attackers to bypass intended access restrictions by leveraging Active Directory certificate trust that should not have remained.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2403

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Printing" component. A format-string vulnerability allows remote attackers to execute arbitrary code via a crafted ipp: or ipps: URL.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2405

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2406

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file.

    Published: 2 Apr 2017
    7.1
    High

    CVE-2017-2409

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Menus" component. It allows attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted app.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2410

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    5.9
    Medium

    CVE-2017-2412

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services by leveraging use of cleartext HTTP.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2413

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "QuickTime" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted media file.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2416

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image file.

    Published: 2 Apr 2017
    5.5
    Medium

    CVE-2017-2417

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to cause a denial of service (infinite recursion) via a crafted image.

    Published: 2 Apr 2017