Show filters
6,927 Total Results
Displaying 51-60 of 6,927
Sort by:
Attacker Value
Unknown
CVE-2016-4655
Disclosure Date: August 25, 2016 (last updated July 03, 2024)
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
1
Attacker Value
Unknown
CVE-2024-44217
Disclosure Date: October 28, 2024 (last updated December 18, 2024)
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may fill in passwords after failing authentication.
1
Attacker Value
Unknown
CVE-2024-44258
Disclosure Date: October 28, 2024 (last updated October 31, 2024)
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
1
Attacker Value
Unknown
CVE-2024-23296
Disclosure Date: March 05, 2024 (last updated August 15, 2024)
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
1
Attacker Value
Unknown
CVE-2024-0869
Disclosure Date: February 05, 2024 (last updated February 14, 2024)
The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in all versions up to, and including, 6.1.0. This makes it possible for authors and higher to update arbitrary options.
1
Attacker Value
Unknown
CVE-2023-42916
Disclosure Date: November 30, 2023 (last updated June 27, 2024)
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
1
Attacker Value
Unknown
CVE-2023-4863
Disclosure Date: September 12, 2023 (last updated December 21, 2024)
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
1
Attacker Value
Unknown
CVE-2023-23514
Disclosure Date: February 27, 2023 (last updated October 08, 2023)
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, macOS Big Sur 11.7.5. An app may be able to execute arbitrary code with kernel privileges.
1
Attacker Value
Unknown
CVE-2023-21721
Disclosure Date: February 14, 2023 (last updated January 11, 2025)
Microsoft OneNote Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2022-42856
Disclosure Date: December 15, 2022 (last updated October 08, 2023)
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
1