Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Total 15410 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4752 1 Apple 1 Mac Os X 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
CVE-2016-4751 1 Apple 1 Safari 2026-06-17 4.3 MEDIUM 3.5 LOW
The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar of a tab via a crafted web site.
CVE-2016-4750 1 Apple 2 Iphone Os, Mac Os X 2026-06-17 9.3 HIGH 7.8 HIGH
S2 Camera in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
CVE-2016-4749 1 Apple 1 Iphone Os 2026-06-17 2.1 LOW 3.3 LOW
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.
CVE-2016-4748 1 Apple 1 Mac Os X 2026-06-17 4.6 MEDIUM 5.3 MEDIUM
Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.
CVE-2016-4747 1 Apple 1 Iphone Os 2026-06-17 4.3 MEDIUM 3.7 LOW
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.
CVE-2016-4746 1 Apple 1 Iphone Os 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.
CVE-2016-4745 1 Apple 1 Mac Os X 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.
CVE-2016-4743 1 Apple 4 Icloud, Iphone Os, Itunes and 1 more 2026-06-17 5.8 MEDIUM 7.1 HIGH
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption and application crash) via a crafted web site.
CVE-2016-4742 1 Apple 1 Mac Os X 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app.
CVE-2016-4741 1 Apple 1 Iphone Os 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
CVE-2016-4740 1 Apple 1 Iphone Os 2026-06-17 1.9 LOW 2.9 LOW
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
CVE-2016-4739 1 Apple 1 Mac Os X 2026-06-17 4.3 MEDIUM 3.7 LOW
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface.
CVE-2016-4738 2 Apple, Debian 5 Iphone Os, Mac Os X, Tvos and 2 more 2026-06-17 9.3 HIGH 8.8 HIGH
libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-4737 1 Apple 4 Iphone Os, Safari, Tvos and 1 more 2026-06-17 9.3 HIGH 8.8 HIGH
WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-4736 1 Apple 1 Mac Os X 2026-06-17 9.3 HIGH 8.8 HIGH
libarchive in Apple OS X before 10.12 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted file.
CVE-2016-4735 1 Apple 3 Iphone Os, Safari, Tvos 2026-06-17 9.3 HIGH 8.8 HIGH
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4734.
CVE-2016-4734 1 Apple 3 Iphone Os, Safari, Tvos 2026-06-17 9.3 HIGH 9.6 CRITICAL
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4735.
CVE-2016-4733 1 Apple 3 Iphone Os, Safari, Tvos 2026-06-17 9.3 HIGH 7.8 HIGH
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4734, and CVE-2016-4735.
CVE-2016-4731 1 Apple 2 Iphone Os, Safari 2026-06-17 9.3 HIGH 8.8 HIGH
WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4729.