CVE-2016-4710
published 2016-09-25CVE-2016-4710: WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.46%
37.8th percentile
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.6 | — |
| apple | macos_sierra | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whh8-chvw-6j23: WindowServer in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2016-4709 [HIGH] CWE-704 GHSA-whh8-chvw-6j23: WindowServer in Apple OS X before 10
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710.
GHSA
GHSA-rwp5-3ghw-68gm: WindowServer in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2016-4710 [HIGH] CWE-704 GHSA-rwp5-3ghw-68gm: WindowServer in Apple OS X before 10
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709.
Apple
CVE-2016-4710: macOS Sierra 10.12
vendor_apple·2016-09-20·CVSS 7.8
CVE-2016-4710 [HIGH] CVE-2016-4710: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4710
Component: WindowServer
Impact: A local user may be able to gain root privileges
Description: A type confusion issue was addressed through improved memory handling.
Cisco
Cisco ACE30 Application Control Engine Module and Cisco ACE 4710 Application Control Engine Denial of Service Vulnerability
vendor_cisco·2016-09-08·CVSS 7.8
CVE-2016-6399 [HIGH] CWE-20 Cisco ACE30 Application Control Engine Module and Cisco ACE 4710 Application Control Engine Denial of Service Vulnerability
Cisco ACE30 Application Control Engine Module and Cisco ACE 4710 Application Control Engine Denial of Service Vulnerability
A vulnerability in the SSL/TLS functions of the Cisco ACE30 Application Control Engine Module and the Cisco ACE 4700 Series Application Control Engine Appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device.
The vulnerability is due to incomplete input validation checks in the SSL/TLS code. An attacker could exploit this vulnerability by sending specific SSL/TLS packets to the affected device. An exploit could allow the attacker to trigger a reload of the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Cisco
Cisco ACE 4710 Application Control Engine Command Injection Vulnerability
vendor_cisco·2016-02-24·CVSS 8.5
CVE-2016-1297 [HIGH] CWE-78 Cisco ACE 4710 Application Control Engine Command Injection Vulnerability
Cisco ACE 4710 Application Control Engine Command Injection Vulnerability
A vulnerability in the Device Manager GUI of the Cisco ACE 4710 Application Control Engine could allow an authenticated, remote attacker to execute any command-line interface (CLI) command on the ACE with admin user privileges.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by crafting a malicious HTTP POST request with injected CLI commands inside the value of a POST parameter value. An exploit could allow the attacker to bypass the role-based access control (RBAC) restrictions enforced by the Cisco ACE Device Manager GUI.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are a
Cisco
Cisco ACE 4710 Application Control Engine Command Injection Vulnerability
vendor_cisco
CVE-2016-1297 Cisco ACE 4710 Application Control Engine Command Injection Vulnerability
CVE-2016-1297: Cisco ACE 4710 Application Control Engine Command Injection Vulnerability
A vulnerability in the Device Manager GUI of the Cisco ACE 4710 Application Control Engine could allow an authenticated, remote attacker to execute any command-line interface (CLI) command on the ACE with admin user privileges. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by crafting a malicious HTTP POST request with injected CLI commands inside the value of a POST parameter value. An exploit could allow the attacker to bypass the role-based access control (RBAC) restrictions enforced by the Cisco ACE Device Manager GUI. Cisco has released software updates that address this vulnerability.
CWE: CWE-78, CWE-78
Bug IDs: CSCul8480
Cisco
Cisco ACE30 Application Control Engine Module and Cisco ACE 4710 Application Control Engine Denial of Service Vulnerability
vendor_cisco
CVE-2016-6399 Cisco ACE30 Application Control Engine Module and Cisco ACE 4710 Application Control Engine Denial of Service Vulnerability
CVE-2016-6399: Cisco ACE30 Application Control Engine Module and Cisco ACE 4710 Application Control Engine Denial of Service Vulnerability
A vulnerability in the SSL/TLS functions of the Cisco ACE30 Application Control Engine Module and the Cisco ACE 4700 Series Application Control Engine Appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incomplete input validation checks in the SSL/TLS code. An attacker could exploit this vulnerability by sending specific SSL/TLS packets to the affected device. An exploit could allow the attacker to trigger a reload of the affected device. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://www.securityfocus.com/bid/93055http://www.securitytracker.com/id/1036858http://www.zerodayinitiative.com/advisories/ZDI-16-608https://support.apple.com/HT207170http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://www.securityfocus.com/bid/93055http://www.securitytracker.com/id/1036858http://www.zerodayinitiative.com/advisories/ZDI-16-608https://support.apple.com/HT207170
2016-09-25
Published