CVE-2016-4776Out-of-bounds Read in Apple Iphone OS

CWE-125Out-of-bounds Read10 documents3 sources
Severity
7.1HIGHNVD
EPSS
0.2%
top 58.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 14

Description

The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4774.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages8 packages

NVDapple/tvos< 10.0
NVDapple/watchos< 3.0
Appleapple/tvos10
NVDapple/mac_os_x< 10.12+1

🔴Vulnerability Details

3
GHSA
GHSA-8rh4-36c6-phxm: The kernel in Apple iOS before 10, OS X before 102022-05-14
GHSA
GHSA-2vhh-4gvf-c7j7: The kernel in Apple iOS before 10, OS X before 102022-05-14
GHSA
GHSA-px39-9mfw-mqmq: The kernel in Apple iOS before 10, OS X before 102022-05-14

📋Vendor Advisories

4
Apple
CVE-2016-4776: macOS Sierra 10.122016-09-20
Apple
CVE-2016-4776: tvOS 102016-09-13
Apple
CVE-2016-4776: iOS 102016-09-13
Apple
CVE-2016-4776: watchOS 32016-09-13