Apple Icloud For Windows vulnerabilities
445 known vulnerabilities affecting apple/icloud_for_windows.
Total CVEs
445
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
10
Severity breakdown
CRITICAL20HIGH346MEDIUM77LOW2
Vulnerabilities
Page 20 of 23
CVE-2016-7586P4MEDIUMCVSS 6.5v6.12016-12-13
CVE-2016-7586 [MEDIUM] CVE-2016-7586: iCloud for Windows 6.1
Apple Security Update: About the security content of iCloud for Windows 6.1
Product: iCloud for Windows
Version: 6.1
CVE: CVE-2016-7586
Component: WebKit
Impact: Processing maliciously crafted web content may result in the disclosure of user information
Description: A validation issue was addressed through improved state management.
apple
CVE-2019-8607P4MEDIUMCVSS 6.5≥ unspecified, < iCloud for Windows 7.122019-12-18
CVE-2019-8607 [MEDIUM] CWE-125 CVE-2019-8607: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may result in the disclosure of process memory.
nvdapple
CVE-2019-7292P4MEDIUMCVSS 6.5≥ unspecified, < iCloud for Windows 7.112019-12-18
CVE-2019-7292 [MEDIUM] CWE-20 CVE-2019-7292: A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, wa
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may result in the disclosure of process memory.
nvdapple
CVE-2019-8515P4MEDIUMCVSS 6.5≥ unspecified, < iCloud for Windows 7.112019-12-18
CVE-2019-8515 [MEDIUM] CWE-20 CVE-2019-8515: A cross-origin issue existed with the fetch API. This was addressed with improved input validation.
A cross-origin issue existed with the fetch API. This was addressed with improved input validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2017-7010P4HIGHCVSS 7.8v6.2.22017-07-19
CVE-2017-7010 [HIGH] CVE-2017-7010: iCloud for Windows 6.2.2
Apple Security Update: About the security content of iCloud for Windows 6.2.2
Product: iCloud for Windows
Version: 6.2.2
CVE: CVE-2017-7010
Component: About Apple security updates
Impact: Parsing a maliciously crafted XML document may lead to disclosure of user information
Description: An out-of-bounds read was addressed through improved bounds checking.
apple
CVE-2017-7013P4HIGHCVSS 7.8v6.2.22017-07-19
CVE-2017-7013 [HIGH] CVE-2017-7013: iCloud for Windows 6.2.2
Apple Security Update: About the security content of iCloud for Windows 6.2.2
Product: iCloud for Windows
Version: 6.2.2
CVE: CVE-2017-7013
Component: About Apple security updates
Impact: Parsing a maliciously crafted XML document may lead to disclosure of user information
Description: An out-of-bounds read was addressed through improved bounds checking.
apple
CVE-2016-4449P4HIGHCVSS 7.1v5.2.12016-07-18
CVE-2016-4449 [HIGH] CVE-2016-4449: iCloud for Windows 5.2.1
Apple Security Update: About the security content of iCloud for Windows 5.2.1
Product: iCloud for Windows
Version: 5.2.1
CVE: CVE-2016-4449
Component: About Apple security updates
Impact: Multiple vulnerabilities in libxml2
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2018-4113P4MEDIUMCVSS 6.5v7.42018-03-29
CVE-2018-4113 [MEDIUM] CVE-2018-4113: iCloud for Windows 7.4
Apple Security Update: About the security content of iCloud for Windows 7.4
Product: iCloud for Windows
Version: 7.4
CVE: CVE-2018-4113
Component: WebKit
Impact: Unexpected interaction with indexing types causing an ASSERT failure
Description: An array indexing issue existed in the handling of a function in javascript core. This issue was addressed through improved checks.
apple
CVE-2017-7106P4MEDIUMCVSS 6.5v7.02017-09-25
CVE-2017-7106 [MEDIUM] CVE-2017-7106: iCloud for Windows 7.0
Apple Security Update: About the security content of iCloud for Windows 7.0
Product: iCloud for Windows
Version: 7.0
CVE: CVE-2017-7106
Component: WebKit
Impact: Visiting a malicious website may lead to address bar spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2017-2493P4MEDIUMCVSS 6.5v6.22017-03-28
CVE-2017-2493 [MEDIUM] CVE-2017-2493: iCloud for Windows 6.2
Apple Security Update: About the security content of iCloud for Windows 6.2
Product: iCloud for Windows
Version: 6.2
CVE: CVE-2017-2493
Component: WebKit
Impact: Processing maliciously crafted web content may exfiltrate data cross-origin
Description: A validation issue existed in element handling. This issue was addressed through improved validation.
apple
CVE-2021-1857P4MEDIUMCVSS 6.5≥ unspecified, < 12.32021-09-08
CVE-2021-1857 [MEDIUM] CWE-665 CVE-2021-1857: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iT
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitiv
nvd
CVE-2017-7153P4MEDIUMCVSS 6.1v7.22017-12-13
CVE-2017-7153 [MEDIUM] CVE-2017-7153: iCloud for Windows 7.2
Apple Security Update: About the security content of iCloud for Windows 7.2
Product: iCloud for Windows
Version: 7.2
CVE: CVE-2017-7153
Component: WebKit
Impact: Visiting a malicious website may lead to user interface spoofing
Description: Redirect responses to 401 Unauthorized may allow a malicious website to incorrectly display the lock icon on mixed content. This issue was addressed through improved URL display logic.
apple
CVE-2019-13118P4MEDIUMCVSS 5.3v10.62019-07-23
CVE-2019-13118 [MEDIUM] CVE-2019-13118: iCloud for Windows 10.6
Apple Security Update: About the security content of iCloud for Windows 10.6
Product: iCloud for Windows
Version: 10.6
CVE: CVE-2019-13118
Component: About Apple security updates
Impact: A remote attacker may be able to view sensitive information
Description: A stack overflow was addressed with improved input validation.
apple
CVE-2018-4273P4MEDIUMCVSS 6.5v7.62018-07-09
CVE-2018-4273 [MEDIUM] CVE-2018-4273: iCloud for Windows 7.6
Apple Security Update: About the security content of iCloud for Windows 7.6
Product: iCloud for Windows
Version: 7.6
CVE: CVE-2018-4273
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2018-4270P4MEDIUMCVSS 6.5v7.62018-07-09
CVE-2018-4270 [MEDIUM] CVE-2018-4270: iCloud for Windows 7.6
Apple Security Update: About the security content of iCloud for Windows 7.6
Product: iCloud for Windows
Version: 7.6
CVE: CVE-2018-4270
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2018-4439P4MEDIUMCVSS 6.5v7.92018-12-05
CVE-2018-4439 [MEDIUM] CVE-2018-4439: iCloud for Windows 7.9
Apple Security Update: About the security content of iCloud for Windows 7.9
Product: iCloud for Windows
Version: 7.9
CVE: CVE-2018-4439
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: A logic issue was addressed with improved validation.
apple
CVE-2016-4613P4MEDIUMCVSS 6.5v6.0.12016-10-27
CVE-2016-4613 [MEDIUM] CVE-2016-4613: iCloud for Windows 6.0.1
Apple Security Update: About the security content of iCloud for Windows 6.0.1
Product: iCloud for Windows
Version: 6.0.1
CVE: CVE-2016-4613
Component: WebKit
Impact: Processing maliciously crafted web content may result in the disclosure of user information
Description: An input validation issue was addressed through improved state management.
apple
CVE-2017-7830P4MEDIUMCVSS 6.5v7.32018-01-23
CVE-2017-7830 [MEDIUM] CVE-2017-7830: iCloud for Windows 7.3
Apple Security Update: About the security content of iCloud for Windows 7.3
Product: iCloud for Windows
Version: 7.3
CVE: CVE-2017-7830
Component: WebKit Page Loading
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4409P4MEDIUMCVSS 6.5v7.82018-10-30
CVE-2018-4409 [MEDIUM] CVE-2018-4409: iCloud for Windows 7.8
Apple Security Update: About the security content of iCloud for Windows 7.8
Product: iCloud for Windows
Version: 7.8
CVE: CVE-2018-4409
Component: WebKit
Impact: A malicious website may be able to cause a denial of service
Description: A resource exhaustion issue was addressed with improved input validation.
apple
CVE-2018-4271P4MEDIUMCVSS 6.5v7.62018-07-09
CVE-2018-4271 [MEDIUM] CVE-2018-4271: iCloud for Windows 7.6
Apple Security Update: About the security content of iCloud for Windows 7.6
Product: iCloud for Windows
Version: 7.6
CVE: CVE-2018-4271
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: Multiple memory corruption issues were addressed with improved input validation.
apple