VYPR

Vendor CVEs

Apple Inc.

All CVEs

9,002 total · sorted by risk
  • CVE-2017-7088MedOct 23, 2017
    risk 0.39cvss 5.9epss 0.02

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext AutoDiscover V1 session during the setup of…

  • CVE-2017-7064MedJul 20, 2017
    risk 0.39cvss 5.5epss 0.07

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass…

  • CVE-2017-6982MedMay 22, 2017
    risk 0.39cvss 5.5epss 0.03

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications" component. It allows attackers to cause a denial of service via a crafted app.

  • CVE-2017-2509MedMay 22, 2017
    risk 0.39cvss 5.5epss 0.03

    An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

  • CVE-2017-2489MedApr 2, 2017
    risk 0.39cvss 5.5epss 0.03

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.

  • CVE-2017-2388MedApr 2, 2017
    risk 0.39cvss 5.5epss 0.06

    An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.

  • CVE-2016-7608MedFeb 20, 2017
    risk 0.39cvss 5.5epss 0.01

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireFamily" component, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.

  • CVE-2016-1788MedMar 24, 2016
    risk 0.39cvss 5.9epss 0.02

    Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages.

  • CVE-2026-65329MedAug 17, 2026
    risk 0.38cvss 5.9epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.

  • CVE-2026-28886MedMar 25, 2026
    risk 0.38cvss 5.9epss 0.01

    A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A user in a privileged…

  • CVE-2024-54494MedDec 12, 2024
    risk 0.38cvss 5.9epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An attacker may be able to create a read-only memory…

  • CVE-2024-54492MedDec 12, 2024
    risk 0.38cvss 5.9epss 0.01

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.

  • CVE-2024-44213MedOct 28, 2024
    risk 0.38cvss 5.9epss 0.01

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker in a privileged network position may be able to leak sensitive user information.

  • CVE-2024-27823MedJul 29, 2024
    risk 0.38cvss 5.9epss 0.01

    A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network…

  • CVE-2024-23277MedMar 8, 2024
    risk 0.38cvss 5.9epss 0.01

    The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard.

  • CVE-2024-1580MedFeb 19, 2024
    risk 0.38cvss 5.9epss 0.02

    An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

  • CVE-2024-23218MedJan 23, 2024
    risk 0.38cvss 5.9epss 0.01

    A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS…

  • CVE-2023-32427MedJul 28, 2023
    risk 0.38cvss 5.9epss 0.00

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 4.2.0 for Android. An attacker in a privileged network position may be able to intercept network traffic.

  • CVE-2023-28321MedMay 26, 2023
    risk 0.38cvss 5.9epss 0.02

    An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one…

  • CVE-2023-23520MedFeb 27, 2023
    risk 0.38cvss 5.9epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read arbitrary files as root.

  • CVE-2021-46841MedFeb 27, 2023
    risk 0.38cvss 5.9epss 0.00

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.

  • CVE-2022-42818MedNov 1, 2022
    risk 0.38cvss 5.9epss 0.01

    This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. A user in a privileged network position may be able to track user activity.

  • CVE-2022-32799MedSep 23, 2022
    risk 0.38cvss 5.9epss 0.01

    An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. A user in a privileged network position may be able to leak sensitive information.

  • CVE-2021-30716MedSep 8, 2021
    risk 0.38cvss 5.9epss 0.02

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to perform denial of service.

  • CVE-2021-30696MedSep 8, 2021
    risk 0.38cvss 5.9epss 0.01

    An attacker in a privileged network position may be able to misrepresent application state. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A logic issue was addressed with improved state management.

  • CVE-2021-1884MedSep 8, 2021
    risk 0.38cvss 5.9epss 0.02

    A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.

  • CVE-2021-30722MedSep 8, 2021
    risk 0.38cvss 5.9epss 0.02

    An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to leak sensitive user…

  • CVE-2021-30982MedAug 24, 2021
    risk 0.38cvss 5.9epss 0.01

    A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A remote attacker may be able to cause unexpected application termination or heap corruption.

  • CVE-2020-9909MedOct 16, 2020
    risk 0.38cvss 5.9epss 0.02

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

  • CVE-2020-9856MedJun 9, 2020
    risk 0.38cvss 5.3epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able to gain elevated privileges.

  • CVE-2020-9801MedJun 9, 2020
    risk 0.38cvss 5.3epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may cause Safari to launch an application.

  • CVE-2019-8663MedDec 18, 2019
    risk 0.38cvss 5.3epss 0.07

    This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory.

  • CVE-2018-4300MedApr 3, 2019
    risk 0.38cvss 5.9epss 0.02

    The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.

  • CVE-2018-4290MedApr 3, 2019
    risk 0.38cvss 5.9epss 0.01

    A denial of service issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, watchOS 4.3.2.

  • CVE-2018-4266MedApr 3, 2019
    risk 0.38cvss 5.9epss 0.02

    A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

  • CVE-2018-4153MedApr 3, 2019
    risk 0.38cvss 5.9epss 0.01

    An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.

  • CVE-2017-2411MedJan 11, 2019
    risk 0.38cvss 5.9epss 0.01

    In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.

  • CVE-2016-4642MedJan 11, 2019
    risk 0.38cvss 5.9epss 0.01

    In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.

  • CVE-2018-4202MedJun 8, 2018
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "iBooks" component. It allows man-in-the-middle attackers to spoof a password prompt.

  • CVE-2018-4174MedApr 3, 2018
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted messages by leveraging an inconsistency in the user interface.

  • CVE-2018-4111MedApr 3, 2018
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that references remote resources but lacks a valid…

  • CVE-2018-4086MedApr 3, 2018
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Security" component. It allows remote attackers to spoof certificate…

  • CVE-2017-7164MedApr 3, 2018
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. The issue involves the "App Store" component. It allows man-in-the-middle attackers to spoof password prompts.

  • CVE-2017-13863MedApr 3, 2018
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle attackers to track users by leveraging the transmission of client certificates.

  • CVE-2017-13864MedDec 25, 2017
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attackers to track users by leveraging mishandling of client…

  • CVE-2017-13860MedDec 25, 2017
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "Mail Drafts" component. It allows man-in-the-middle attackers to read e-mail content by leveraging mishandling of S/MIME credential…

  • CVE-2017-9579MedJun 16, 2017
    risk 0.38cvss 5.9epss 0.01

    The "JMCU Mobile Banking" by Joplin Metro Credit Union app 3.0.0 -- aka jmcu-mobile-banking/id716065893 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted…

  • CVE-2017-6988MedMay 22, 2017
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote attackers to discover the network credentials of arbitrary users by operating a crafted network that requires 802.1X authentication,…

  • CVE-2017-2448MedApr 2, 2017
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. The issue involves the "Keychain" component. It allows man-in-the-middle attackers to bypass an iCloud Keychain secret protection…

  • CVE-2017-2412MedApr 2, 2017
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services by leveraging use of cleartext HTTP.

Page 72 of 181