Advisories
watchOSExploitedCISA KEV listedHIGH2017-04-02
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute ar...
CVEs:CVE-2017-2490
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSExploitedCISA KEV listedHIGH2017-04-02
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
CVEs:CVE-2017-2489
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2017-04-13
Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.
CVEs:CVE-2010-1816
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2017-04-24
Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code.
CVEs:CVE-2011-3428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2017-04-03
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScri...
CVEs:CVE-2017-5949
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
SafariEPSS <= 49%HIGH2017-04-03
runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a ...
CVEs:CVE-2016-10222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
SafariEPSS <= 49%HIGH2017-04-03
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that is mishandled in the operatorStr...
CVEs:CVE-2016-10226
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2017-04-24
WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution.
CVEs:CVE-2011-3438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
macOSEPSS <= 49%CRITICAL2017-04-02
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "libxslt" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via u...
CVEs:CVE-2017-2477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
iOSEPSS <= 49%MEDIUM2017-04-24
Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to wipe the device.
CVEs:CVE-2010-1776
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
iOSEPSS <= 49%CRITICAL2017-04-04
Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom...
CVEs:CVE-2017-6975
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| iphone_os |
affected |
apple |
— |
— |
macOSEPSS <= 49%HIGH2017-04-13
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
CVEs:CVE-2010-1821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2017-04-07
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVEs:CVE-2017-2387
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apple_music |
affected |
apple |
— |
— |