CVE-2016-4683
https://notcve.org/view.php?id=CVE-2016-4683
20 Feb 2017 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted SGI file. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra al componente "ImageIO". • http://www.securityfocus.com/bid/94431 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4681
https://notcve.org/view.php?id=CVE-2016-4681
20 Feb 2017 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Core Image" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG file. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra al componente "Core Image". • http://www.securityfocus.com/bid/94431 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-7580
https://notcve.org/view.php?id=CVE-2016-7580
20 Feb 2017 — An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves the "Mail" component, which allows remote web servers to cause a denial of service via a crafted URL. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12 está afectado. El problema involucra al componente "Mail", que permite a servidores web remotos provocar una denegación de servicio a través de una URL manipulada. • http://www.securityfocus.com/bid/94434 • CWE-20: Improper Input Validation •
CVE-2016-7613
https://notcve.org/view.php?id=CVE-2016-7613
20 Feb 2017 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages object-lifetime mishandling during process spawning. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versiones anterior... • http://www.securityfocus.com/bid/94116 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-4721
https://notcve.org/view.php?id=CVE-2016-4721
20 Feb 2017 — An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "IDS - Connectivity" component, which allows man-in-the-middle attackers to spoof calls via a "switch caller" notification. Se ha descubierto un problema en ciertos productos Apple. iOS en versiones anteriores a 10.1 está afectado. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra al componente "IDS - Connectivity" que permite a atacantes man-in-... • http://www.securityfocus.com/bid/94429 • CWE-254: 7PK - Security Features •
CVE-2016-7618
https://notcve.org/view.php?id=CVE-2016-7618
20 Feb 2017 — An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .gcx file. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.2 está afectado. El problema involucra al componente "Foundation". • http://www.securityfocus.com/bid/94903 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2016-4780
https://notcve.org/view.php?id=CVE-2016-4780
20 Feb 2017 — An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Thunderbolt" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.1 está afectado. El problema involucra al componente "Thunderbolt". • https://support.apple.com/HT207275 • CWE-476: NULL Pointer Dereference •
CVE-2016-7742
https://notcve.org/view.php?id=CVE-2016-7742
20 Feb 2017 — An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" component, which allows remote attackers to execute arbitrary code via a crafted archive that triggers use of uninitialized memory locations. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.2 está afectado. El problema involucra al componente "xar", que permite a atacantes remotos ejecutar código arbitrario a través de un archivo manipulado que des... • https://support.apple.com/HT207423 • CWE-20: Improper Input Validation •
CVE-2017-2358
https://notcve.org/view.php?id=CVE-2017-2358
24 Jan 2017 — An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Graphics Drivers" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.3 está afectado. El problema involucra al componente "Graphics Drivers". • http://www.securityfocus.com/bid/95723 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-2357
https://notcve.org/view.php?id=CVE-2017-2357
24 Jan 2017 — An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "IOAudioFamily" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app. Se ha descubierto un problema en ciertos productos Apple. macOS en versiones anteriores a 10.12.3 está afectado. El problema involucra al componente "IOAudioFamily". • http://www.securityfocus.com/bid/95723 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •