Apple

macOS X

3207 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.87%
  • Veröffentlicht 19.06.2016 20:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846.

  • EPSS 0.17%
  • Veröffentlicht 19.06.2016 20:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.

  • EPSS 1.2%
  • Veröffentlicht 09.06.2016 16:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Exploit
  • EPSS 3.33%
  • Veröffentlicht 09.06.2016 16:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.

  • EPSS 1.5%
  • Veröffentlicht 26.05.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

Exploit
  • EPSS 6.63%
  • Veröffentlicht 20.05.2016 11:00:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute...

  • EPSS 11.14%
  • Veröffentlicht 20.05.2016 11:00:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar...

Exploit
  • EPSS 32.58%
  • Veröffentlicht 20.05.2016 11:00:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via format string specifiers in an SNMP::get call.

  • EPSS 1.29%
  • Veröffentlicht 20.05.2016 11:00:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.

  • EPSS 0.09%
  • Veröffentlicht 20.05.2016 11:00:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Screen Lock feature in Apple OS X before 10.11.5 mishandles password profiles, which allows physically proximate attackers to reset expired passwords in the lock-screen state via unspecified vectors.