Apple Security Advisories · June 2016 — Apple Security Advisories
7 advisories 7 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2016-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-1861

macOSExploitedCISA KEV listedHIGH2016-06-19

The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846.

CVEs:CVE-2016-1861

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2016-1864

iOSPoC exploitCRITICAL2016-06-19

The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.

CVEs:CVE-2016-1864

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2015-7988

OtherEPSS <= 49%CRITICAL2016-06-20

The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors.

CVEs:CVE-2015-7988

Affected products

ProductStatusVendorPackageEcosystem
airport_base_station_firmware affected apple
iphone_os affected apple
mac_os_x affected apple
mdnsresponder affected apple
watchos affected apple
Upstream advisory

CVE-2015-7029

OtherEPSS <= 49%HIGH2016-06-20

Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2015-7029

Affected products

ProductStatusVendorPackageEcosystem
airport_base_station_firmware affected apple
Upstream advisory

CVE-2015-7987

OtherEPSS <= 49%CRITICAL2016-06-20

Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import, or (4) CopyNSEC3Resource...

CVEs:CVE-2015-7987

Affected products

ProductStatusVendorPackageEcosystem
airport_base_station_firmware affected apple
iphone_os affected apple
mac_os_x affected apple
mdnsresponder affected apple
watchos affected apple
Upstream advisory

CVE-2016-1860

macOSEPSS <= 49%MEDIUM2016-06-19

Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.

CVEs:CVE-2016-1860

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2016-1862

macOSEPSS <= 49%MEDIUM2016-06-19

Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.

CVEs:CVE-2016-1862

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.