CVE-2016-7598 – Apple Security Advisory 2016-12-13-4
https://notcve.org/view.php?id=CVE-2016-7598
14 Dec 2016 — An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. • http://www.securityfocus.com/bid/94907 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-7641 – Apple Security Advisory 2016-12-13-4
https://notcve.org/view.php?id=CVE-2016-7641
14 Dec 2016 — An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. • http://www.securityfocus.com/bid/94907 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-7650 – Apple Security Advisory 2016-12-13-5
https://notcve.org/view.php?id=CVE-2016-7650
14 Dec 2016 — An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "Safari Reader" component, which allows remote attackers to conduct UXSS attacks via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. Safari en versiones anteriores a 10.0.2 está afectado. • http://www.securityfocus.com/bid/94915 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-7592 – Apple Security Advisory 2016-12-13-4
https://notcve.org/view.php?id=CVE-2016-7592
14 Dec 2016 — An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. Safari en versiones anteriores a 10.0.2 está afectado. iCloud en versiones... • http://www.securityfocus.com/bid/94909 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-7610 – Apple Safari RenderObject Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-7610
13 Dec 2016 — An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. • http://www.securityfocus.com/bid/94907 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-7611 – Apple Safari HTMLLabelElement Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-7611
13 Dec 2016 — An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.2 está afectado. • http://www.securityfocus.com/bid/94907 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-7578 – Ubuntu Security Notice USN-3166-1
https://notcve.org/view.php?id=CVE-2016-7578
28 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. • http://www.securityfocus.com/bid/93949 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4613 – Ubuntu Security Notice USN-3166-1
https://notcve.org/view.php?id=CVE-2016-4613
28 Oct 2016 — An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. • http://www.securityfocus.com/bid/93949 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-4677 – Apple Safari JavaScriptCore Array Out-Of-Bounds Access Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-4677
24 Oct 2016 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. • http://www.securityfocus.com/bid/93853 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4676 – Apple Security Advisory 2016-10-24-3
https://notcve.org/view.php?id=CVE-2016-4676
24 Oct 2016 — A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information. Se presenta una vulnerabilidad de origen cruzado en WebKit en Apple Safari versiones anteriores a 10.0.1 al procesar atributos de ubicación, lo que podría permitir a un usuario malicioso remoto obtener información confidencial. Safari 10.0.1 is now available and addresses code execution vulnerabilities. • http://seclists.org/fulldisclosure/2016/Oct/89 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •