CVE-2016-1850
- EPSS 0.53%
- Published 20.05.2016 11:00:03
- Last modified 12.04.2025 10:46:40
SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
CVE-2016-1848
- EPSS 3.34%
- Published 20.05.2016 11:00:01
- Last modified 12.04.2025 10:46:40
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
CVE-2016-1847
- EPSS 0.86%
- Published 20.05.2016 11:00:00
- Last modified 12.04.2025 10:46:40
OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-1846
- EPSS 1%
- Published 20.05.2016 10:59:59
- Last modified 12.04.2025 10:46:40
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference and memory corru...
CVE-2016-1844
- EPSS 1.15%
- Published 20.05.2016 10:59:58
- Last modified 12.04.2025 10:46:40
The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.
CVE-2016-1843
- EPSS 1.29%
- Published 20.05.2016 10:59:57
- Last modified 12.04.2025 10:46:40
The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVE-2016-1842
- EPSS 1.15%
- Published 20.05.2016 10:59:56
- Last modified 12.04.2025 10:46:40
MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
CVE-2016-1841
- EPSS 1.68%
- Published 20.05.2016 10:59:55
- Last modified 12.04.2025 10:46:40
libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-1840
- EPSS 2.14%
- Published 20.05.2016 10:59:54
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause...
CVE-2016-1839
- EPSS 10.77%
- Published 20.05.2016 10:59:53
- Last modified 12.04.2025 10:46:40
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craft...