CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-2418

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Hypervisor" component. It allows guest OS users to obtain sensitive information from the CR8 control register via unspecified vectors.

    Published: 2 Apr 2017
    7.5
    High

    CVE-2017-2419

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass a Content Security Policy protection mechanism via unspecified vectors.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2420

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 2 Apr 2017
    6.5
    Medium

    CVE-2017-2424

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves mishandling of OpenGL shaders in the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2425

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "SecurityFoundation" component. A double free vulnerability allows remote attackers to execute arbitrary code via a crafted certificate.

    Published: 2 Apr 2017
    3.3
    Low

    CVE-2017-2426

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "iBooks" component. It allows remote attackers to obtain sensitive information from local files via a file: URL in an iBooks file.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2427

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2430

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted audio file.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2431

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "CoreMedia" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .mov file.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2432

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG file.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2433

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    9.8
    Critical

    CVE-2017-2434

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "HomeKit" component. It allows attackers to have an unspecified impact by leveraging the presence of Home Control on Control Center.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2437

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireAVC" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2438

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "AppleRAID" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Published: 2 Apr 2017
    7.1
    High

    CVE-2017-2439

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted font file.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2440

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (integer overflow) via a crafted app.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2441

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "libc++abi" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code via a crafted C++ app that is mishandled during demangling.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2444

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    6.1
    Medium

    CVE-2017-2445

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2446

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages the mishandling of strict mode functions.

    Published: 2 Apr 2017
    8.1
    High

    CVE-2017-2447

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.

    Published: 2 Apr 2017
    5.9
    Medium

    CVE-2017-2448

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. The issue involves the "Keychain" component. It allows man-in-the-middle attackers to bypass an iCloud Keychain secret protection mechanism by leveraging lack of authentication for OTR packets.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2451

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Security" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.

    Published: 2 Apr 2017
    4.6
    Medium

    CVE-2017-2452

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to read text messages on the lock screen via unspecified vectors.

    Published: 2 Apr 2017
    6.5
    Medium

    CVE-2017-2453

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof FaceTime prompts in the user interface via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2454

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2455

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2458

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Keyboards" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2459

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2460

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    7.5
    High

    CVE-2017-2461

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2462

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted audio file.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2465

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2466

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2467

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2468

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2471

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS before 3.2 is affected. The issue involves the "WebKit" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2472

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2473

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2474

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    6.1
    Medium

    CVE-2017-2475

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted use of frames on a web site.

    Published: 2 Apr 2017
    7
    High

    CVE-2017-2478

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    6.5
    Medium

    CVE-2017-2480

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 2 Apr 2017
    8.8
    High

    CVE-2017-2481

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 2 Apr 2017
    7.8
    High

    CVE-2017-2482

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 2 Apr 2017
    5.5
    Medium

    CVE-2017-2489

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.

    Published: 2 Apr 2017
    5.5
    Medium

    CVE-2017-6974

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the "System Integrity Protection" component. It allows attackers to modify the contents of a protected disk location via a crafted app.

    Published: 2 Apr 2017
    3.3
    Low

    CVE-2017-2404

    Last Modified: 6 May 2026

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Quick Look" component. It allows remote attackers to trigger telephone calls to arbitrary numbers via a tel: URL in a PDF document, as exploited in the wild in October 2016.

    Published: 2 Apr 2017
    6.5
    Medium

    CVE-2017-2367

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 2 Apr 2017
    9.8
    Critical

    CVE-2017-5645

    Last Modified: 20 Apr 2025

    In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

    Published: 2 Apr 2017