VYPR

SoftwareUpdate

by Apple Inc.

CVEs (3)

  • CVE-2016-1731MedMar 14, 2016
    risk 0.38cvss 5.9epss 0.01

    Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.

  • CVE-2007-0463Jan 29, 2007
    risk 0.04cvss epss 0.18

    Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3)…

  • CVE-2002-0676Jul 11, 2002
    risk 0.03cvss epss 0.04

    SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse…