CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2016-4664

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata via a crafted app.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2016-4665

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read audio-recording metadata via a crafted app.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4666

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-4667

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4671

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) via a crafted PDF file.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4674

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4675

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-4680

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4681

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Core Image" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG file.

    Published: 20 Feb 2017
    7.1
    High

    CVE-2016-4682

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12 is affected. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted SGI file.

    Published: 20 Feb 2017
    4.4
    Medium

    CVE-2016-4686

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "Contacts" component, which does not prevent an app's Address Book access after access revocation.

    Published: 20 Feb 2017
    7.5
    High

    CVE-2016-4689

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Mail" component, which does not alert the user to an S/MIME email signature that used a revoked certificate.

    Published: 20 Feb 2017
    6.8
    Medium

    CVE-2016-4690

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Image Capture" component, which allows attackers to execute arbitrary code via a crafted USB HID device.

    Published: 20 Feb 2017
    7.1
    High

    CVE-2016-4743

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-4780

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Thunderbolt" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 Feb 2017
    3.7
    Low

    CVE-2016-7577

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "FaceTime" component, which allows remote attackers to trigger memory corruption and obtain audio data from a call that appeared to have ended.

    Published: 20 Feb 2017
    4.3
    Medium

    CVE-2016-7581

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "Safari" component, which allows remote web servers to cause a denial of service via a crafted URL.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7583

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iCloud before 6.0.1 is affected. The issue involves the setup subsystem in the "iCloud" component. It allows local users to gain privileges via a crafted dynamic library in an unspecified directory.

    Published: 20 Feb 2017
    4.3
    Medium

    CVE-2016-7592

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7596

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    4.6
    Medium

    CVE-2016-7597

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to maintain the unlocked state via vectors related to Handoff with Siri.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-7598

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory via a crafted web site.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-7599

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP redirects.

    Published: 20 Feb 2017
    6.2
    Medium

    CVE-2016-7600

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "OpenPAM" component, which allows local users to obtain sensitive information by leveraging mishandling of failed PAM authentication by a sandboxed app.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7603

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreStorage" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7604

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreCapture" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7605

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7607

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component, which allows attackers to obtain sensitive information from kernel memory via a crafted app.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7611

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7613

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages object-lifetime mishandling during process spawning.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7614

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iCloud before 6.1 is affected. The issue involves the "Windows Security" component. It allows local users to obtain sensitive information from iCloud desktop-client process memory via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7617

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (type confusion) via a crafted app.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7618

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .gcx file.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7619

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "libarchive" component, which allows local users to write to arbitrary files via vectors related to symlinks.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2016-7620

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOSurface" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7621

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via unspecified vectors.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2016-7624

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOAcceleratorFamily" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2016-7625

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOKit" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-7627

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreGraphics" component. It allows attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted font.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7628

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Assets" component, which allows local users to bypass intended permission restrictions and change a downloaded mobile asset via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7633

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory Services" component. It allows local users to gain privileges or cause a denial of service (use-after-free) via unspecified vectors.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7635

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    4.7
    Medium

    CVE-2016-7650

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "Safari Reader" component, which allows remote attackers to conduct UXSS attacks via a crafted web site.

    Published: 20 Feb 2017
    4.6
    Medium

    CVE-2016-7638

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Find My iPhone" component, which allows physically proximate attackers to disable this component by bypassing authentication.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7639

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7640

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7641

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7642

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7645

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7646

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017