5.5
    Medium

    CVE-2017-2509

    Last Modified: 22 May 2017

    An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Source:Google Security Research
    Published:22 May 2017
    6.1
    Medium

    CVE-2017-2508

    Last Modified: 25 May 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.

    Source:Google Security Research
    Published:22 May 2017
    6.1
    Medium

    CVE-2017-2504

    Last Modified: 25 May 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands.

    Source:Google Security Research
    Published:22 May 2017
    7
    High

    CVE-2017-2501

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:22 May 2017
    8.8
    High

    CVE-2017-2491

    Last Modified: 5 May 2017

    Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitrary code via a crafted web page, or a crafted file.

    Source:saelo & niklasb
    Published:27 Jun 2017
    7.8
    High

    CVE-2017-2490

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    5.5
    Medium

    CVE-2017-2489

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    7.8
    High

    CVE-2017-2483

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    7.8
    High

    CVE-2017-2482

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    6.5
    Medium

    CVE-2017-2480

    Last Modified: 11 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    6.5
    Medium

    CVE-2017-2479

    Last Modified: 11 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    7
    High

    CVE-2017-2478

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2476

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    7.8
    High

    CVE-2017-2474

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    7.8
    High

    CVE-2017-2473

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    7.8
    High

    CVE-2017-2472

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2471

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS before 3.2 is affected. The issue involves the "WebKit" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2470

    Last Modified: 11 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2469

    Last Modified: 11 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2468

    Last Modified: 11 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2466

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2464

    Last Modified: 25 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2460

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2459

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2457

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    7
    High

    CVE-2017-2456

    Last Modified: 1 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2455

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2454

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.1
    High

    CVE-2017-2447

    Last Modified: 27 Mar 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2446

    Last Modified: 27 Mar 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages the mishandling of strict mode functions.

    Source:Google Security Research
    Published:2 Apr 2017
    6.1
    Medium

    CVE-2017-2445

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.

    Source:Google Security Research
    Published:2 Apr 2017
    7.8
    High

    CVE-2017-2443

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:2 Apr 2017
    6.5
    Medium

    CVE-2017-2442

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    5.5
    Medium

    CVE-2017-2388

    Last Modified: 3 Mar 2018

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.

    Source:Brandon Azad
    Published:2 Apr 2017
    8.8
    High

    CVE-2017-2373

    Last Modified: 1 Feb 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    6.5
    Medium

    CVE-2017-2371

    Last Modified: 24 Feb 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2017-2370

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.

    Source:Google Security Research
    Published:20 Feb 2017
    8.8
    High

    CVE-2017-2369

    Last Modified: 1 Feb 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    5.5
    Medium

    CVE-2017-2368

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.

    Published:20 Feb 2017
    6.5
    Medium

    CVE-2017-2367

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Source:Google Security Research
    Published:2 Apr 2017
    6.5
    Medium

    CVE-2017-2365

    Last Modified: 24 Feb 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    6.5
    Medium

    CVE-2017-2364

    Last Modified: 4 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    6.5
    Medium

    CVE-2017-2363

    Last Modified: 24 Feb 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    8.8
    High

    CVE-2017-2362

    Last Modified: 1 Feb 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    6.1
    Medium

    CVE-2017-2361

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2017-2360

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2017-2353

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Source:Google Security Research
    Published:20 Feb 2017
    8
    High

    CVE-2017-1635

    Last Modified: 20 Apr 2025

    IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243.

    Published:13 Dec 2017
    7.3
    High

    CVE-2017-1297

    Last Modified: 26 Jun 2017

    IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.

    Source:defensecode
    Published:27 Jun 2017
    8.8
    High

    CVE-2017-1274

    Last Modified: 8 May 2019

    IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.

    Source:Charles Truscott
    Published:25 Apr 2017