CVE-2016-4685
https://notcve.org/view.php?id=CVE-2016-4685
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "iTunes Backup" component, which improperly hashes passwords, making it easier to decrypt files. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. El problema involucra el componente "iTunes Backup" que indebidamente hashea contraseñas haciendo más fácil descifrar archivos. • http://www.securityfocus.com/bid/94432 https://support.apple.com/HT207271 • CWE-326: Inadequate Encryption Strength •
CVE-2017-2352
https://notcve.org/view.php?id=CVE-2017-2352
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Unlock with iPhone" component, which allows attackers to bypass the wrist-presence protection mechanism and unlock a Watch device via unspecified vectors. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2.1 está afectado. watchOS en versiones anteriores a 3.1.3 está afectado. El problema involucra al componente "Unlock with iPhone", que permite a atacantes eludir el mecanismo de protección de presencia de muñeca y desbloquear un dispositivo Watch a través de vectores no especificados. • http://www.securityfocus.com/bid/95730 http://www.securitytracker.com/id/1037668 https://support.apple.com/HT207482 https://support.apple.com/HT207487 •
CVE-2017-2371 – Apple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Bypass
https://notcve.org/view.php?id=CVE-2017-2371
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2.1 está afectado. El problema involucra al componente "WebKit" que permite a atacantes remotos enviar ventanas emergentes a través de un sito web manipulado. • https://www.exploit-db.com/exploits/41451 http://www.securityfocus.com/bid/95735 http://www.securitytracker.com/id/1037668 https://security.gentoo.org/glsa/201706-15 https://support.apple.com/HT207482 • CWE-20: Improper Input Validation •
CVE-2017-2368
https://notcve.org/view.php?id=CVE-2017-2368
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2.1 está afectado. El problema involucra al componente "Contacts". • https://github.com/vincedes3/CVE-2017-2368 http://www.securityfocus.com/bid/95722 http://www.securitytracker.com/id/1037668 https://support.apple.com/HT207482 • CWE-20: Improper Input Validation •
CVE-2017-2350
https://notcve.org/view.php?id=CVE-2017-2350
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2.1 está afectado. • http://www.securityfocus.com/bid/95727 http://www.securitytracker.com/id/1037668 https://security.gentoo.org/glsa/201706-15 https://support.apple.com/HT207482 https://support.apple.com/HT207484 https://support.apple.com/HT207485 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •