CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-1843

    Last Modified: 12 Apr 2025

    The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 20 May 2016
    3.3
    Low

    CVE-2016-1849

    Last Modified: 12 Apr 2025

    The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.

    Published: 20 May 2016
    7.5
    High

    CVE-2016-1853

    Last Modified: 12 Apr 2025

    Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1857

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1804

    Last Modified: 12 Apr 2025

    The Multi-Touch subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1805

    Last Modified: 12 Apr 2025

    CoreStorage in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 20 May 2016
    5.1
    Medium

    CVE-2016-1807

    Last Modified: 12 Apr 2025

    Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to obtain sensitive information from kernel memory via unspecified vectors.

    Published: 20 May 2016
    5.5
    Medium

    CVE-2016-1814

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1820

    Last Modified: 12 Apr 2025

    Buffer overflow in IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1823

    Last Modified: 12 Apr 2025

    The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read and memory corruption) via a crafted IOHIDReportType enum, which triggers an incorrect cast, a different vulnerability than CVE-2016-1824.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1828

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.

    Published: 20 May 2016
    5.5
    Medium

    CVE-2016-1836

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1830

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1828, and CVE-2016-1829.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1831

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3.2 and OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1742

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 20 May 2016
    3.3
    Low

    CVE-2016-1790

    Last Modified: 12 Apr 2025

    Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

    Published: 20 May 2016
    3.3
    Low

    CVE-2016-1791

    Last Modified: 12 Apr 2025

    The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1792

    Last Modified: 12 Apr 2025

    The AMD subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1793

    Last Modified: 12 Apr 2025

    AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1794

    Last Modified: 12 Apr 2025

    The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 May 2016
    3.3
    Low

    CVE-2016-1796

    Last Modified: 12 Apr 2025

    Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1797

    Last Modified: 12 Apr 2025

    Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbitrary code in a privileged context via a crafted app.

    Published: 20 May 2016
    3.3
    Low

    CVE-2016-1798

    Last Modified: 12 Apr 2025

    Audio in Apple OS X before 10.11.5 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1800

    Last Modified: 12 Apr 2025

    Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.

    Published: 20 May 2016
    7.5
    High

    CVE-2016-1801

    Last Modified: 12 Apr 2025

    The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 20 May 2016
    5.5
    Medium

    CVE-2016-1802

    Last Modified: 12 Apr 2025

    CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive information via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1803

    Last Modified: 12 Apr 2025

    CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1806

    Last Modified: 12 Apr 2025

    Crash Reporter in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1808

    Last Modified: 12 Apr 2025

    The Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    7.5
    High

    CVE-2016-1809

    Last Modified: 12 Apr 2025

    Disk Utility in Apple OS X before 10.11.5 uses incorrect encryption keys for disk images, which has unspecified impact and attack vectors.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1810

    Last Modified: 12 Apr 2025

    The Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    6.5
    Medium

    CVE-2016-1811

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1815

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1816

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1818

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016-1819.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1826

    Last Modified: 12 Apr 2025

    Integer overflow in the dtrace implementation in the kernel in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1821

    Last Modified: 12 Apr 2025

    IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1822

    Last Modified: 12 Apr 2025

    IOFireWireFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1824

    Last Modified: 12 Apr 2025

    IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1823.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1825

    Last Modified: 12 Apr 2025

    IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1835

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a crafted XML document.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1832

    Last Modified: 12 Apr 2025

    libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 20 May 2016
    5.5
    Medium

    CVE-2016-1838

    Last Modified: 12 Apr 2025

    The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

    Published: 20 May 2016
    5.5
    Medium

    CVE-2016-1839

    Last Modified: 12 Apr 2025

    The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1848

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.

    Published: 20 May 2016
    7.5
    High

    CVE-2016-1842

    Last Modified: 12 Apr 2025

    MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.

    Published: 20 May 2016
    5.3
    Medium

    CVE-2016-1844

    Last Modified: 12 Apr 2025

    The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.

    Published: 20 May 2016
    7.8
    High

    CVE-2016-1846

    Last Modified: 12 Apr 2025

    The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference and memory corruption) via a crafted app.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1847

    Last Modified: 12 Apr 2025

    OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 20 May 2016
    4.6
    Medium

    CVE-2016-1851

    Last Modified: 12 Apr 2025

    The Screen Lock feature in Apple OS X before 10.11.5 mishandles password profiles, which allows physically proximate attackers to reset expired passwords in the lock-screen state via unspecified vectors.

    Published: 20 May 2016