![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1778 – Apple Safari Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-1778
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 permite a atacantes remotos ejecutar código arbitrario o causar un denegación de servicio (corrupción de memoria) a través de un sitio web manipulado. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1779 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1779
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 permite a atacantes remotos eludir la Same Origin Policy y obtener datos de localización física a través de una petición de geolocalización manipulada. WebKitGTK+ versions prior to 2.10.5 suffers from memory corruption, code execution, missing ... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1780 – Apple Security Advisory 2016-03-21-1
https://notcve.org/view.php?id=CVE-2016-1780
22 Mar 2016 — WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site. WebKit en Apple iOS en versiones anteriores a 9.3 no impide a vistas de web ocultas la lectura de datos de orientación y movimiento, lo que permite a atacantes remotos obtener información sensible sobre el entorno físico del dispositivo a través de un sitio web manipulado. iOS 9.3... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1781 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1781
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 no gestiona correctamente las URLs adjuntadas, lo que facilita a servidores web remotos rastrear a usuarios a través de vectores no especificados. WebKitGTK+ versions prior to 2.10.5 suffers from memory corruption, code execution, missing restriction, and d... • http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html • CWE-19: Data Processing Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1782 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1782
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 no restringe correctamente los redireccionamientos que especifican un número de puerto TCP, lo que permite a atacantes remotos eludir las restricciones de puerto previstas a través de un sitio web manipulado. W... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-284: Improper Access Control •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1783 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1783
22 Mar 2016 — WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. WebKit en Apple iOS en versiones anteriores a 9.3, Safari en versiones anteriores a 9.1 y tvOS en versiones anteriores a 9.2 permite a atacantes remotos ejecutar código arbitrario o causar un denegación de servicio (corrupción de memoria) a través de un sitio web manipulado. WebKitGTK+ versions prior to 2.10.5 suffer... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1784 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1784
22 Mar 2016 — The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) via a crafted web site. La implementación History en WebKit en Apple iOS en versiones anteriores a 9.3, Safari en versiones anteriores a 9.1 y tvOS en versiones anteriores a 9.2 permite a atacantes remotos causar una denegación de servicio (consumo de recurso y caída de aplicación) a través de un sitio web manip... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-400: Uncontrolled Resource Consumption •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1785 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1785
22 Mar 2016 — The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. La implementación Page Loading en WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 no gestiona correctamente el codificado de caracteres durante el acceso a los datos cacheados, lo que permite a atacantes... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1786 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1786
22 Mar 2016 — The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site. La implementación Page Loading en WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 no gestiona correctamente las respuestas HTTP con un código de estado 3xx (tambi... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-1788 – Apple Security Advisory 2016-03-21-2
https://notcve.org/view.php?id=CVE-2016-1788
22 Mar 2016 — Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages. Messages en Apple iOS en versiones anteriores a 9.3, OS X en versiones anteriores a 10.11.4 y watchOS en versiones anteriores a 2.2 no implementa correctamente un mecanismo de protección criptográfico, lo que permite a atacantes remotos leer contenidos adjuntos de lo... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-310: Cryptographic Issues •