CVE-2016-1844Improper Access Control in Apple MAC OS X

Severity
5.3MEDIUMNVD
EPSS
1.2%
top 21.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateMay 17

Description

The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

🔴Vulnerability Details

1
GHSA
GHSA-77qc-55hq-3c2q: The Messages component in Apple OS X before 102022-05-17

📋Vendor Advisories

1
Apple
CVE-2016-1844: OS X El Capitan v10.11.5 and Security Update 2016-003

💬Community

13
Bugzilla
CVE-2015-8934 libarchive: out of bounds heap read in RAR parser2016-06-23
Bugzilla
CVE-2015-8930 libarchive: Endless loop in ISO parser2016-06-23
Bugzilla
CVE-2015-8923 libarchive: Unclear crashes in ZIP parser2016-06-22
Bugzilla
CVE-2015-8931 libarchive: Undefined behavior (signed integer overflow) in mtree parser2016-06-22
Bugzilla
CVE-2015-8922 libarchive: NULL pointer access in 7z parser2016-06-21