CVE-2016-4652
published 2016-07-22CVE-2016-4652: CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or cause a…
PriorityP426medium6.3CVSS 3.0
AVLACHPRLUINSUCHINAH
EPSS
0.29%
21.8th percentile
CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or cause a denial of service (out-of-bounds read), via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.5 | — |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h997-r486-qvm7: CoreGraphics in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2016-4652 [MEDIUM] CWE-125 GHSA-h997-r486-qvm7: CoreGraphics in Apple OS X before 10
CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or cause a denial of service (out-of-bounds read), via unspecified vectors.
Apple
CVE-2016-4652: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 6.3
CVE-2016-4652 [MEDIUM] CVE-2016-4652: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-4652
Component: CoreGraphics
Impact: A local user may be able to elevate privileges
Description: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed through improved input validation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348http://zerodayinitiative.com/advisories/ZDI-16-432/https://support.apple.com/HT206903http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348http://zerodayinitiative.com/advisories/ZDI-16-432/https://support.apple.com/HT206903
2016-07-22
Published