Apple

iPhone OS

4014 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 25.09.2016 10:59:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output.

  • EPSS 4.17%
  • Veröffentlicht 25.09.2016 10:59:15
  • Zuletzt bearbeitet 06.05.2026 22:30:45

CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.

  • EPSS 0.06%
  • Veröffentlicht 25.09.2016 10:59:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.

  • EPSS 17.73%
  • Veröffentlicht 25.09.2016 10:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Audio in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

  • EPSS 0.27%
  • Veröffentlicht 25.09.2016 10:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

  • EPSS 11.27%
  • Veröffentlicht 25.09.2016 10:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary co...

  • EPSS 0.5%
  • Veröffentlicht 25.09.2016 10:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."

  • EPSS 0.92%
  • Veröffentlicht 25.09.2016 10:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733...

  • EPSS 0.06%
  • Veröffentlicht 18.09.2016 22:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.

  • EPSS 0.17%
  • Veröffentlicht 18.09.2016 22:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.