CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2016-4661

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" component, which misparses disk images and allows attackers to cause a denial of service via a crafted app.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4677

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-4679

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows remote attackers to write to arbitrary files via a crafted archive containing a symlink.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4683

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted SGI file.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4688

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted font.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4691

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.

    Published: 20 Feb 2017
    6.8
    Medium

    CVE-2016-4781

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to bypass the passcode attempt counter and unlock a device via unspecified vectors.

    Published: 20 Feb 2017
    7.1
    High

    CVE-2016-4660

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted font.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4669

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (MIG code mishandling and system crash) via unspecified vectors.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2016-4670

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "Security" component. It allows local users to discover lengths of arbitrary passwords by reading a log.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4673

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG file.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4678

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleSMC" component. It allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 20 Feb 2017
    5.9
    Medium

    CVE-2016-4685

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "iTunes Backup" component, which improperly hashes passwords, making it easier to decrypt files.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4692

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    7.5
    High

    CVE-2016-4693

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which makes it easier for attackers to bypass cryptographic protection mechanisms by leveraging use of the 3DES cipher.

    Published: 20 Feb 2017
    5.9
    Medium

    CVE-2016-4721

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "IDS - Connectivity" component, which allows man-in-the-middle attackers to spoof calls via a "switch caller" notification.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4764

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10 is affected. Safari before 10 is affected. iTunes before 12.5.1 is affected. tvOS before 10 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7612

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7616

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Disk Images" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-7623

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a blob URL on a web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7626

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS before 3.1.1 is affected. The issue involves the "Profiles" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted certificate profile.

    Published: 20 Feb 2017
    9.8
    Critical

    CVE-2016-7630

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebSheet" component, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.

    Published: 20 Feb 2017
    4.6
    Medium

    CVE-2016-7634

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Accessibility" component, which accepts spoken passwords without considering that they are locally audible.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7637

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7644

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Published: 20 Feb 2017
    5.3
    Medium

    CVE-2016-7651

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by leveraging the mishandling of an app uninstall.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7652

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7659

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7666

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Transporter before 1.9.2 is affected. The issue involves the "iTMSTransporter" component, which allows attackers to obtain sensitive information via a crafted EPUB.

    Published: 20 Feb 2017
    2.4
    Low

    CVE-2016-7765

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Clipboard" component, which allows physically proximate attackers to obtain sensitive information in the lockscreen state by viewing clipboard contents.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2017-2350

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2354

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2017-2358

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Graphics Drivers" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2017-2371

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2017-2374

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-7580

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves the "Mail" component, which allows remote web servers to cause a denial of service via a crafted URL.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7582

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7584

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "AppleMobileFileIntegrity" component, which allows remote attackers to spoof signed code by using a matching team ID.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7588

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreMedia Playback" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted MP4 file.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7589

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-7591

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOHIDFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7595

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7602

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7606

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    6.2
    Medium

    CVE-2016-7609

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "AppleGraphicsPowerManagement" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7610

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-4613

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4617

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process spawning in the "libxpc" component.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4662

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleGraphicsControl" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-4663

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017