CVE-2016-4737Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Iphone OS

Severity
8.8HIGHNVD
EPSS
2.0%
top 16.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 14

Description

WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

NVDapple/safari< 10.0
NVDapple/watchos< 3.0
NVDapple/tvos10.0
Appleapple/tvos10
Appleapple/safari10

🔴Vulnerability Details

2
GHSA
GHSA-gfc6-rx62-f4mq: WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a den2022-05-14
OSV
CVE-2016-4737: WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a den2016-09-25

📋Vendor Advisories

4
Apple
CVE-2016-4737: Safari 102016-09-20
Apple
CVE-2016-4737: tvOS 102016-09-13
Apple
CVE-2016-4737: watchOS 32016-09-13
Apple
CVE-2016-4737: iOS 102016-09-13