
CVE-2016-4675 – Apple Security Advisory 2016-10-24-1
https://notcve.org/view.php?id=CVE-2016-4675
24 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versiones anteriores a 10.12.1 está afectado. tvOS en versiones anteriores a 10.0.1 e... • http://www.securityfocus.com/bid/93849 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-4678 – Apple OS X AppleSMC smcHandleYPCEvent Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2016-4678
24 Oct 2016 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleSMC" component. It allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra al componente "AppleSMC". • http://www.securityfocus.com/bid/93852 • CWE-476: NULL Pointer Dereference •

CVE-2016-4679 – Apple Security Advisory 2016-10-24-1
https://notcve.org/view.php?id=CVE-2016-4679
24 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows remote attackers to write to arbitrary files via a crafted archive containing a symlink. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versiones anteriores a 10.12.1 está afectado. tvOS en versiones ante... • http://www.securityfocus.com/bid/93849 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2016-4682 – Apple Security Advisory 2016-10-24-2
https://notcve.org/view.php?id=CVE-2016-4682
24 Oct 2016 — An issue was discovered in certain Apple products. macOS before 10.12 is affected. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted SGI file. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12 está afectado. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra el compo... • http://www.securityfocus.com/bid/93852 • CWE-125: Out-of-bounds Read •

CVE-2016-4748
https://notcve.org/view.php?id=CVE-2016-4748
25 Sep 2016 — Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable. Perl en Apple OS X en versiones anteriores a 10.12 permite a usuarios locales eludir el mecanismo de protección a través de un entorno variable manipulado. • http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html • CWE-254: 7PK - Security Features •

CVE-2016-4696
https://notcve.org/view.php?id=CVE-2016-4696
25 Sep 2016 — AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app. AppleEFIRuntime en Apple OS X en versiones anteriores a 10.12 permite a atacantes ejecutar un código arbitrario en un contexto privilegiado o provocar una denegación de servicio (referencia a puntero NULL) a través de una app manipulada. • http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html • CWE-476: NULL Pointer Dereference •

CVE-2016-4701
https://notcve.org/view.php?id=CVE-2016-4701
25 Sep 2016 — Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable. Application Firewall en Apple OS X en versiones anteriores a 10.12 permite a usuarios locales provocar una denegación de servicio a través de vectores relacionados con un entorno variable SO_EXECPATH manipulado. • http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html • CWE-20: Improper Input Validation •

CVE-2016-4703
https://notcve.org/view.php?id=CVE-2016-4703
25 Sep 2016 — Bluetooth in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Bluetooth en Apple OS X en versiones anteriores a 10.12 permite a atacantes ejecutar un código arbitrario en un contexto privilegiado o provocar una denegación de servicio (corrupción de memoria) a través de una app manipulada. • http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-4706
https://notcve.org/view.php?id=CVE-2016-4706
25 Sep 2016 — cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors. cd9660 en Apple OS X en versiones anteriores a 10.12 permite a usuarios locales provocar una denegación de servicio a través de vectores no especificados. • http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html • CWE-20: Improper Input Validation •

CVE-2016-4709 – Apple OS X WindowServer _XSetPerUserConfigurationData Type Confusion Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2016-4709
25 Sep 2016 — WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710. WindowServer en Apple OS X en versiones anteriores a 10.12 permite a usuarios locales obtener acceso de root a través de vectores que desencadenan una "confusión de tipo", una vulnerabilidad diferente a CVE-2016-4710. This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Apple OS X. An attacker ... • http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html • CWE-704: Incorrect Type Conversion or Cast •