CVE-2016-4660 – Apple Security Advisory 2016-10-24-1
https://notcve.org/view.php?id=CVE-2016-4660
24 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted font. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versiones anteriore... • http://www.securityfocus.com/bid/93849 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-4663 – Apple Security Advisory 2016-10-24-2
https://notcve.org/view.php?id=CVE-2016-4663
24 Oct 2016 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra el componente "NVIDIA Graphics Drivers". • http://www.securityfocus.com/bid/93852 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4676 – Apple Security Advisory 2016-10-24-3
https://notcve.org/view.php?id=CVE-2016-4676
24 Oct 2016 — A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information. Se presenta una vulnerabilidad de origen cruzado en WebKit en Apple Safari versiones anteriores a 10.0.1 al procesar atributos de ubicación, lo que podría permitir a un usuario malicioso remoto obtener información confidencial. Safari 10.0.1 is now available and addresses code execution vulnerabilities. • http://seclists.org/fulldisclosure/2016/Oct/89 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-4679 – Apple Security Advisory 2016-10-24-1
https://notcve.org/view.php?id=CVE-2016-4679
24 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows remote attackers to write to arbitrary files via a crafted archive containing a symlink. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versiones anteriores a 10.12.1 está afectado. tvOS en versiones ante... • http://www.securityfocus.com/bid/93849 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2016-4662 – Apple Security Advisory 2016-10-24-2
https://notcve.org/view.php?id=CVE-2016-4662
24 Oct 2016 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleGraphicsControl" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra el componente "AppleGraphicsControl". • http://www.securityfocus.com/bid/93852 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4675 – Apple Security Advisory 2016-10-24-1
https://notcve.org/view.php?id=CVE-2016-4675
24 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versiones anteriores a 10.12.1 está afectado. tvOS en versiones anteriores a 10.0.1 e... • http://www.securityfocus.com/bid/93849 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-4667 – Apple Security Advisory 2016-10-24-2
https://notcve.org/view.php?id=CVE-2016-4667
24 Oct 2016 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra al componente "ATS". • http://www.securityfocus.com/bid/93852 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4661 – Apple Security Advisory 2016-10-24-2
https://notcve.org/view.php?id=CVE-2016-4661
24 Oct 2016 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" component, which misparses disk images and allows attackers to cause a denial of service via a crafted app. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra el componente "ntfs", que difunde imágenes del disco y permite a atacantes provocar una denegación del servicio a través de una aplicación manipulada. mac... • http://www.securityfocus.com/bid/93852 • CWE-20: Improper Input Validation •
CVE-2016-4669 – Apple OS X/iOS - 'mach_ports_register' Multiple Memory Safety s
https://notcve.org/view.php?id=CVE-2016-4669
24 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (MIG code mishandling and system crash) via unspecified vectors. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versione... • https://packetstorm.news/files/id/158874 • CWE-20: Improper Input Validation •
CVE-2016-4682 – Apple Security Advisory 2016-10-24-2
https://notcve.org/view.php?id=CVE-2016-4682
24 Oct 2016 — An issue was discovered in certain Apple products. macOS before 10.12 is affected. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted SGI file. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12 está afectado. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra el compo... • http://www.securityfocus.com/bid/93852 • CWE-125: Out-of-bounds Read •