CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-2197

    Last Modified: 12 Apr 2025

    Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that places text in a crafted context, leading to unintended use of that text within a Safari dialog.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1736

    Last Modified: 12 Apr 2025

    Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1735.

    Published: 24 Mar 2016
    5.5
    Medium

    CVE-2016-1745

    Last Modified: 12 Apr 2025

    IOFireWireFamily in Apple OS X before 10.11.4 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1750

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1753

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allow attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1754

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1755.

    Published: 24 Mar 2016
    3.5
    Low

    CVE-2016-1763

    Last Modified: 12 Apr 2025

    Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.

    Published: 24 Mar 2016
    4.3
    Medium

    CVE-2016-1772

    Last Modified: 12 Apr 2025

    The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors.

    Published: 24 Mar 2016
    5.3
    Medium

    CVE-2016-1774

    Last Modified: 12 Apr 2025

    The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.

    Published: 24 Mar 2016
    4.3
    Medium

    CVE-2016-1780

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site.

    Published: 24 Mar 2016
    5.9
    Medium

    CVE-2016-1788

    Last Modified: 12 Apr 2025

    Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages.

    Published: 24 Mar 2016
    9.1
    Critical

    CVE-2015-6853

    Last Modified: 12 Apr 2025

    The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.

    Published: 24 Mar 2016
    9.1
    Critical

    CVE-2015-6854

    Last Modified: 12 Apr 2025

    The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.

    Published: 24 Mar 2016
    4.3
    Medium

    CVE-2016-1764

    Last Modified: 12 Apr 2025

    The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows remote attackers to obtain sensitive information via a javascript: URL.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1769

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Photoshop file.

    Published: 24 Mar 2016
    6.1
    Medium

    CVE-2016-1599

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 24 Mar 2016
    6.5
    Medium

    CVE-2016-1770

    Last Modified: 12 Apr 2025

    The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing action via a tel: URL.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1733

    Last Modified: 12 Apr 2025

    AppleRAID in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 24 Mar 2016
    6.8
    Medium

    CVE-2016-1734

    Last Modified: 12 Apr 2025

    AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted USB device.

    Published: 24 Mar 2016
    6.3
    Medium

    CVE-2016-1737

    Last Modified: 12 Apr 2025

    Carbon in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dfont file.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1738

    Last Modified: 12 Apr 2025

    dyld in Apple OS X before 10.11.4 allows attackers to bypass a code-signing protection mechanism via a modified app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1740

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.

    Published: 24 Mar 2016
    9.8
    Critical

    CVE-2016-1741

    Last Modified: 12 Apr 2025

    The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1743

    Last Modified: 12 Apr 2025

    The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1744.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1746

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1747.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1747

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1746.

    Published: 24 Mar 2016
    3.3
    Low

    CVE-2016-1748

    Last Modified: 12 Apr 2025

    IOHIDFamily in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1749

    Last Modified: 12 Apr 2025

    IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1751

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3, tvOS before 9.2, and watchOS before 2.2 does not properly restrict the execute permission, which allows attackers to bypass a code-signing protection mechanism via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1755

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1756

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 24 Mar 2016
    7
    High

    CVE-2016-1757

    Last Modified: 12 Apr 2025

    Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 24 Mar 2016
    3.3
    Low

    CVE-2016-1758

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1759

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1765

    Last Modified: 12 Apr 2025

    otool in Apple Xcode before 7.3 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors.

    Published: 24 Mar 2016
    7.5
    High

    CVE-2016-1766

    Last Modified: 12 Apr 2025

    The Profiles component in Apple iOS before 9.3 does not properly validate certificates, which allows attackers to spoof an MDM profile trust relationship via unspecified vectors.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1768

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1767.

    Published: 24 Mar 2016
    3.3
    Low

    CVE-2016-1773

    Last Modified: 12 Apr 2025

    The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1775

    Last Modified: 12 Apr 2025

    TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.

    Published: 24 Mar 2016
    5.3
    Medium

    CVE-2016-1776

    Last Modified: 12 Apr 2025

    Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.

    Published: 24 Mar 2016
    7.5
    High

    CVE-2016-1777

    Last Modified: 12 Apr 2025

    Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

    Published: 24 Mar 2016
    8.8
    High

    CVE-2016-1778

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 24 Mar 2016
    4.3
    Medium

    CVE-2016-1781

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.

    Published: 24 Mar 2016
    6.5
    Medium

    CVE-2016-1782

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site.

    Published: 24 Mar 2016
    6.5
    Medium

    CVE-2016-1784

    Last Modified: 12 Apr 2025

    The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) via a crafted web site.

    Published: 24 Mar 2016
    6.5
    Medium

    CVE-2016-1785

    Last Modified: 12 Apr 2025

    The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 24 Mar 2016
    8.8
    High

    CVE-2016-1646

    Last Modified: 21 Apr 2026

    The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 24 Mar 2016
    8.8
    High

    CVE-2016-3679

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 24 Mar 2016
    8.8
    High

    CVE-2016-1650

    Last Modified: 12 Apr 2025

    The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of service or possibly have unspecified other impact by triggering an error in creating an MHTML document.

    Published: 24 Mar 2016
    8.8
    High

    CVE-2016-1647

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 24 Mar 2016