Apple
apple
8,851 CVEs • 196 products
Products (196)
Click to collapseToggle
Products (196)
Click to collapse
CVEs (8,851)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that places text in a crafted context, leading to unintended use of that text within a Safari dialog. |
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream. |
4Apple MozillaOpensuse+1 more12Firefox Glassfish ServerIphone Os+9 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreMay 6, 2026 Feb 15, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreMay 6, 2026 Feb 15, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via...Show more |
6Apple CanonicalDebian+3 more6Debian Linux LeapNginx+3 moreMay 6, 2026 Feb 15, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response. |
2Apple Google5Android Iphone OsMac Os X+2 moreMay 6, 2026 Feb 7, 2016 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v...Show more |
2Apple Google5Android Iphone OsMac Os X+2 moreMay 6, 2026 Feb 7, 2016 N/A· v4 9.8 CRITICAL· v3 8.3 HIGH· v2 The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v...Show more |
WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal. |
Untrusted search path vulnerability in OSA Scripts in Apple OS X before 10.11.3 allows attackers to load arbitrary script libraries via a quarantined application. |
The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain...Show more |
2Apple Webkitgtk5Iphone Os SafariTvos+2 moreMay 6, 2026 Feb 1, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a differen...Show more |
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than...Show more |
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than...Show more |
2Apple Webkitgtk5Iphone Os SafariTvos+2 moreMay 6, 2026 Feb 1, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a differen...Show more |
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 Feb 1, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors. |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 Feb 1, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors. |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 Feb 1, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors. |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 Feb 1, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors. |