CVE-2016-7651
https://notcve.org/view.php?id=CVE-2016-7651
An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by leveraging the mishandling of an app uninstall. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. watchOS en versiones anteriores a 3.1.1 está afectado. El problema involucra al componente "Accounts", que permite a usuarios locales eludir las restricciones destinadas a autorización aprovechando el manejo incorrecto de una app de desinstalación. • http://www.securityfocus.com/bid/94851 http://www.securitytracker.com/id/1037429 https://lists.apple.com/archives/security-announce/2016/Dec/msg00001.html https://support.apple.com/HT207422 https://support.apple.com/HT207487 • CWE-285: Improper Authorization •
CVE-2016-7626 – iOS 10.1.x - Certificate File Memory Corruption
https://notcve.org/view.php?id=CVE-2016-7626
An issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS before 3.1.1 is affected. The issue involves the "Profiles" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted certificate profile. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. tvOS en versiones anteriores a 10.1 está afectado. watchOS en versiones anteriores a 3.1.1 está afectado. El problema involucra al componente "Profiles". • https://www.exploit-db.com/exploits/40906 http://www.securityfocus.com/bid/94852 http://www.securitytracker.com/id/1037429 https://lists.apple.com/archives/security-announce/2016/Dec/msg00001.html https://support.apple.com/HT207422 https://support.apple.com/HT207425 https://support.apple.com/HT207487 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4665
https://notcve.org/view.php?id=CVE-2016-4665
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read audio-recording metadata via a crafted app. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. tvOS en versiones anteriores a 10.0.1 está afectado. watchOS en versiones anteriores a 3.1 está afectado. El problema involucra el componente "Sandbox Profiles" que permite a atacantes leer los metadatos de audio-grabaciones a través de una aplicación manipulada. • http://www.securityfocus.com/bid/93854 http://www.securitytracker.com/id/1037088 https://support.apple.com/HT207269 https://support.apple.com/HT207270 https://support.apple.com/HT207271 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-4680
https://notcve.org/view.php?id=CVE-2016-4680
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. tvOS en versiones anteriores a 10.0.1 está afectado. watchOS en versiones anteriores a 3.1 está afectado. El problema involucra al componente "Kernel". • http://www.securityfocus.com/bid/93854 http://www.securitytracker.com/id/1037088 https://support.apple.com/HT207269 https://support.apple.com/HT207270 https://support.apple.com/HT207271 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-4664
https://notcve.org/view.php?id=CVE-2016-4664
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata via a crafted app. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. tvOS en versiones anteriores a 10.0.1 está afectado. watchOS en versiones anteriores a 3.1 está afectado. El problema involucra el componente "Sandbox Profiles" que permite a atacantes leer los metadatos de foto-directorio a través de una aplicación manipulada. • http://www.securityfocus.com/bid/93854 http://www.securitytracker.com/id/1037088 https://support.apple.com/HT207269 https://support.apple.com/HT207270 https://support.apple.com/HT207271 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •