Vulnerabilities (CVE)

Filtered by CWE-200
Total 11065 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4739 1 Apple 1 Mac Os X 2026-06-17 4.3 MEDIUM 3.7 LOW
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface.
CVE-2016-4719 1 Apple 2 Iphone Os, Watchos 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.
CVE-2016-4715 1 Apple 1 Mac Os X 2026-06-17 4.3 MEDIUM 3.3 LOW
The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.
CVE-2016-4713 1 Apple 1 Mac Os X 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.
CVE-2016-4711 1 Apple 2 Iphone Os, Mac Os X 2026-06-17 5.0 MEDIUM 7.5 HIGH
CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output.
CVE-2016-4708 1 Apple 4 Iphone Os, Mac Os X, Tvos and 1 more 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.
CVE-2016-4707 1 Apple 2 Iphone Os, Mac Os X 2026-06-17 2.1 LOW 4.0 MEDIUM
CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.
CVE-2016-4680 1 Apple 3 Iphone Os, Tvos, Watchos 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
CVE-2016-4676 1 Apple 2 Mac Os X, Safari 2026-06-17 5.0 MEDIUM 7.5 HIGH
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
CVE-2016-4665 1 Apple 3 Iphone Os, Tvos, Watchos 2026-06-17 4.3 MEDIUM 3.3 LOW
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read audio-recording metadata via a crafted app.
CVE-2016-4664 1 Apple 3 Iphone Os, Tvos, Watchos 2026-06-17 4.3 MEDIUM 3.3 LOW
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata via a crafted app.
CVE-2016-4660 1 Apple 4 Iphone Os, Mac Os X, Tvos and 1 more 2026-06-17 5.8 MEDIUM 7.1 HIGH
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted font.
CVE-2016-4648 1 Apple 1 Mac Os X 2026-06-17 4.9 MEDIUM 5.5 MEDIUM
Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds read) via unspecified vectors.
CVE-2016-4646 1 Apple 1 Mac Os X 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted audio file.
CVE-2016-4645 1 Apple 1 Mac Os X 2026-06-17 2.1 LOW 3.3 LOW
CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.
CVE-2016-4644 1 Apple 3 Apple Tv, Iphone Os, Mac Os 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
CVE-2016-4643 1 Apple 3 Apple Tv, Iphone Os, Mac Os 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.
CVE-2016-4635 1 Apple 2 Iphone Os, Mac Os X 2026-06-17 3.5 LOW 5.3 MEDIUM
FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive audio information in opportunistic circumstances, via unspecified vectors.
CVE-2016-4628 1 Apple 2 Iphone Os, Watchos 2026-06-17 4.9 MEDIUM 5.5 MEDIUM
IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via unspecified vectors.
CVE-2016-4620 1 Apple 1 Iphone Os 2026-06-17 4.3 MEDIUM 3.3 LOW
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.