
CVE-2016-1856 – Apple Safari TextTrack Object Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-1856
17 May 2016 — WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857. WebKit, como se utiliza en Apple iOS en versiones anteriores a 9.3.2, Safari en versiones anteriores a 9.1.1 y tvOS en versiones anteriores a 9.2.1, permite a atacantes remotos ejecutar código arbitrario o causar una deneg... • http://lists.apple.com/archives/security-announce/2016/May/msg00001.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-1857 – Apple Safari ArrayStorage DFG Optimization Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-1857
17 May 2016 — WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856. WebKit, como se utiliza en Apple iOS en versiones anteriores a 9.3.2, Safari en versiones anteriores a 9.1.1 y tvOS en versiones anteriores a 9.2.1, permite a atacantes remotos ejecutar código arbitrario o causar una deneg... • http://lists.apple.com/archives/security-announce/2016/May/msg00001.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-1858 – Apple Security Advisory 2016-05-16-1
https://notcve.org/view.php?id=CVE-2016-1858
17 May 2016 — WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site. WebKit, como se utiliza en Apple iOS en versiones anteriores a 9.3.2, Safari en versiones anteriores a 9.1.1 y tvOS en versiones anteriores a 9.2.1, no maneja adecuadamente el seguimiento de los atributos taint, lo que permite a atacantes remotos obtener información sensible a través de una página web ... • http://lists.apple.com/archives/security-announce/2016/May/msg00001.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-1859 – Apple Safari GraphicsContext Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-1859
17 May 2016 — The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. La implementación WebKit Canvas en Apple iOS en versiones anteriores a 9.3.2, Safari en versiones anteriores a 9.1.1 y tvOS en versiones anteriores a 9.2.1 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de una... • http://lists.apple.com/archives/security-announce/2016/May/msg00001.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-1771 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1771
22 Mar 2016 — The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site. La funcionalidad Downloads en Apple Safari en versiones anteriores a 9.1 no gestiona correctamente la expansión de archivo, lo que permite a atacantes remotos causar un denegación de servicio a través de un sitio web manipulado. Safari 9.1 is now available and addresses code execution, interface spoofing, denial of service, and various other vulnerabi... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html • CWE-19: Data Processing Errors •

CVE-2016-1772 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1772
22 Mar 2016 — The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors. La funcionalidad Top Sites en Apple Safari en versiones anteriores a 9.1 no gestiona correctamente el almacenamiento de cookies, lo que facilita a servidores web remotos rastrear usuarios a través de vectores no especificados. Safari 9.1 is now available and addresses code execution, interface spoofing, denial of service, and various other vulnerabi... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-1778 – Apple Safari Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-1778
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 permite a atacantes remotos ejecutar código arbitrario o causar un denegación de servicio (corrupción de memoria) a través de un sitio web manipulado. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-399: Resource Management Errors •

CVE-2016-1779 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1779
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 permite a atacantes remotos eludir la Same Origin Policy y obtener datos de localización física a través de una petición de geolocalización manipulada. WebKitGTK+ versions prior to 2.10.5 suffers from memory corruption, code execution, missing ... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-1781 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1781
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 no gestiona correctamente las URLs adjuntadas, lo que facilita a servidores web remotos rastrear a usuarios a través de vectores no especificados. WebKitGTK+ versions prior to 2.10.5 suffers from memory corruption, code execution, missing restriction, and d... • http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html • CWE-19: Data Processing Errors •

CVE-2016-1782 – Apple Security Advisory 2016-03-21-6
https://notcve.org/view.php?id=CVE-2016-1782
22 Mar 2016 — WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site. WebKit en Apple iOS en versiones anteriores a 9.3 y Safari en versiones anteriores a 9.1 no restringe correctamente los redireccionamientos que especifican un número de puerto TCP, lo que permite a atacantes remotos eludir las restricciones de puerto previstas a través de un sitio web manipulado. W... • http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html • CWE-284: Improper Access Control •