CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
99221 | CVE-2017-2401 | Candidate | An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99222 | CVE-2017-2402 | Candidate | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of profile uninstall actions in the "MCX Client" component when a profile has multiple payloads. It allows remote attackers to bypass intended access restrictions by leveraging Active Directory certificate trust that should not have remained. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99223 | CVE-2017-2403 | Candidate | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Printing" component. A format-string vulnerability allows remote attackers to execute arbitrary code via a crafted ipp: or ipps: URL. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99224 | CVE-2017-2404 | Candidate | An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Quick Look" component. It allows remote attackers to trigger telephone calls to arbitrary numbers via a tel: URL in a PDF document, as exploited in the wild in October 2016. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99225 | CVE-2017-2405 | Candidate | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | Assigned (20161201) | None (candidate not yet proposed) | View |
Page 19845 of 20943, showing 5 records out of 104715 total, starting on record 99221, ending on 99225