CVE-2016-1782
- EPSS 0.7%
- Veröffentlicht 24.03.2016 01:59:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site.
CVE-2016-1781
- EPSS 0.46%
- Veröffentlicht 24.03.2016 01:59:48
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.
CVE-2016-1780
- EPSS 0.27%
- Veröffentlicht 24.03.2016 01:59:47
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site.
CVE-2016-1779
- EPSS 7.67%
- Veröffentlicht 24.03.2016 01:59:46
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request.
CVE-2016-1778
- EPSS 1.21%
- Veröffentlicht 24.03.2016 01:59:45
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-1775
- EPSS 0.98%
- Veröffentlicht 24.03.2016 01:59:42
- Zuletzt bearbeitet 12.04.2025 10:46:40
TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
CVE-2016-1766
- EPSS 0.15%
- Veröffentlicht 24.03.2016 01:59:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Profiles component in Apple iOS before 9.3 does not properly validate certificates, which allows attackers to spoof an MDM profile trust relationship via unspecified vectors.
CVE-2016-1763
- EPSS 0.21%
- Veröffentlicht 24.03.2016 01:59:31
- Zuletzt bearbeitet 12.04.2025 10:46:40
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.
CVE-2016-1762
- EPSS 8.58%
- Veröffentlicht 24.03.2016 01:59:30
- Zuletzt bearbeitet 17.12.2025 22:15:52
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
- EPSS 13.95%
- Veröffentlicht 24.03.2016 01:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.