Apple Security Advisories · April 2017 — Apple Security Advisories
13 advisories 13 CVEs 2 EXPLOITED

Apple-vendor CVEs for 2017-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2017-2490

watchOSExploitedCISA KEV listedHIGH2017-04-02

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute ar...

CVEs:CVE-2017-2490

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-2489

macOSExploitedCISA KEV listedHIGH2017-04-02

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.

CVEs:CVE-2017-2489

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2010-1816

macOSEPSS <= 49%HIGH2017-04-13

Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.

CVEs:CVE-2010-1816

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2011-3428

OtherEPSS <= 49%CRITICAL2017-04-24

Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code.

CVEs:CVE-2011-3428

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2017-5949

SafariEPSS <= 49%CRITICAL2017-04-03

JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScri...

CVEs:CVE-2017-5949

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2016-10222

SafariEPSS <= 49%HIGH2017-04-03

runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a ...

CVEs:CVE-2016-10222

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2016-10226

SafariEPSS <= 49%HIGH2017-04-03

JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that is mishandled in the operatorStr...

CVEs:CVE-2016-10226

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2011-3438

SafariEPSS <= 49%CRITICAL2017-04-24

WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution.

CVEs:CVE-2011-3438

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2017-2477

macOSEPSS <= 49%CRITICAL2017-04-02

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "libxslt" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via u...

CVEs:CVE-2017-2477

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2010-1776

iOSEPSS <= 49%MEDIUM2017-04-24

Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to wipe the device.

CVEs:CVE-2010-1776

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2017-6975

iOSEPSS <= 49%CRITICAL2017-04-04

Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom...

CVEs:CVE-2017-6975

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2010-1821

macOSEPSS <= 49%HIGH2017-04-13

Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.

CVEs:CVE-2010-1821

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2017-2387

OtherEPSS <= 49%HIGH2017-04-07

The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVEs:CVE-2017-2387

Affected products

ProductStatusVendorPackageEcosystem
apple_music affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.