cbcvebase.

Apple Icloud For Windows vulnerabilities

445 known vulnerabilities affecting apple/icloud_for_windows.

Total CVEs
445
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
10
Severity breakdown
CRITICAL20HIGH346MEDIUM77LOW2

Vulnerabilities

Page 22 of 23
CVE-2016-4743P4HIGHCVSS 7.1v6.12016-12-13
CVE-2016-4743 [HIGH] CVE-2016-4743: iCloud for Windows 6.1 Apple Security Update: About the security content of iCloud for Windows 6.1 Product: iCloud for Windows Version: 6.1 CVE: CVE-2016-4743 Component: WebKit Impact: Processing maliciously crafted web content may result in the disclosure of process memory Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-1836P4MEDIUMCVSS 5.5v5.2.12016-07-18
CVE-2016-1836 [MEDIUM] CVE-2016-1836: iCloud for Windows 5.2.1 Apple Security Update: About the security content of iCloud for Windows 5.2.1 Product: iCloud for Windows Version: 5.2.1 CVE: CVE-2016-1836 Component: About Apple security updates Impact: Multiple vulnerabilities in libxml2 Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2018-4309P4MEDIUMCVSS 6.1v7.72018-10-08
CVE-2018-4309 [MEDIUM] CVE-2018-4309: iCloud for Windows 7.7 Apple Security Update: About the security content of iCloud for Windows 7.7 Product: iCloud for Windows Version: 7.7 CVE: CVE-2018-4309 Component: WebKit Impact: A malicious website may be able to execute scripts in the context of another website Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4345P4MEDIUMCVSS 6.1v7.72018-10-08
CVE-2018-4345 [MEDIUM] CVE-2018-4345: iCloud for Windows 7.7 Apple Security Update: About the security content of iCloud for Windows 7.7 Product: iCloud for Windows Version: 7.7 CVE: CVE-2018-4345 Component: WebKit Impact: A malicious website may exfiltrate image data cross-origin Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4377P4MEDIUMCVSS 6.1v7.82018-10-30
CVE-2018-4377 [MEDIUM] CVE-2018-4377: iCloud for Windows 7.8 Apple Security Update: About the security content of iCloud for Windows 7.8 Product: iCloud for Windows Version: 7.8 CVE: CVE-2018-4377 Component: Safari Reader Impact: Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4293P4MEDIUMCVSS 5.3v7.62018-07-09
CVE-2018-4293 [MEDIUM] CVE-2018-4293: iCloud for Windows 7.6 Apple Security Update: About the security content of iCloud for Windows 7.6 Product: iCloud for Windows Version: 7.6 CVE: CVE-2018-4293 Component: CFNetwork Impact: Cookies may unexpectedly persist in Safari Description: A cookie management issue was addressed with improved checks.
apple
CVE-2019-8764P4MEDIUMCVSS 6.1v7.142019-10-07
CVE-2019-8764 [MEDIUM] CVE-2019-8764: iCloud for Windows 7.14 Apple Security Update: About the security content of iCloud for Windows 7.14 Product: iCloud for Windows Version: 7.14 CVE: CVE-2019-8764 Component: WebKit Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management.
apple
CVE-2017-7109P4MEDIUMCVSS 6.1v7.02017-09-25
CVE-2017-7109 [MEDIUM] CVE-2017-7109: iCloud for Windows 7.0 Apple Security Update: About the security content of iCloud for Windows 7.0 Product: iCloud for Windows Version: 7.0 CVE: CVE-2017-7109 Component: WebKit Impact: Processing maliciously crafted web content may lead to a cross site scripting attack Description: Application Cache policy may be unexpectedly applied.
apple
CVE-2017-13831P4HIGHCVSS 7.1v7.02017-09-25
CVE-2017-13831 [HIGH] CVE-2017-13831: iCloud for Windows 7.0 Apple Security Update: About the security content of iCloud for Windows 7.0 Product: iCloud for Windows Version: 7.0 CVE: CVE-2017-13831 Component: ImageIO Impact: Processing a maliciously crafted image may lead to a denial of service Description: An information disclosure issue existed in the processing of disk images. This issue was addressed through improved memory management.
apple
CVE-2019-8582P4MEDIUMCVSS 5.5v7.122019-05-28
CVE-2019-8582 [MEDIUM] CVE-2019-8582: iCloud for Windows 7.12 Apple Security Update: About the security content of iCloud for Windows 7.12 Product: iCloud for Windows Version: 7.12 CVE: CVE-2019-8582 Component: CoreText Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2018-4224P4MEDIUMCVSS 5.5v7.52018-06-01
CVE-2018-4224 [MEDIUM] CVE-2018-4224: iCloud for Windows 7.5 Apple Security Update: About the security content of iCloud for Windows 7.5 Product: iCloud for Windows Version: 7.5 CVE: CVE-2018-4224 Component: Security Impact: A local user may be able to read a persistent device identifier Description: An authorization issue was addressed with improved state management.
apple
CVE-2018-4232P4MEDIUMCVSS 4.3v7.52018-06-01
CVE-2018-4232 [MEDIUM] CVE-2018-4232: iCloud for Windows 7.5 Apple Security Update: About the security content of iCloud for Windows 7.5 Product: iCloud for Windows Version: 7.5 CVE: CVE-2018-4232 Component: WebKit Impact: Visiting a maliciously crafted website may lead to cookies being overwritten Description: A permissions issue existed in the handling of web browser cookies. This issue was addressed with improved restrictions.
apple
CVE-2020-3885P4MEDIUMCVSS 4.3≥ unspecified, < iCloud for Windows 10.9.3≥ unspecified, < iCloud for Windows 7.182020-04-01
CVE-2020-3885 [MEDIUM] CWE-670 CVE-2020-3885: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.
nvd
CVE-2019-8834P4MEDIUMCVSS 4.3v10.92019-12-11
CVE-2019-8834 [MEDIUM] CVE-2019-8834: iCloud for Windows 10.9 Apple Security Update: About the security content of iCloud for Windows 10.9 Product: iCloud for Windows Version: 10.9 CVE: CVE-2019-8834 Component: CFNetwork Impact: An attacker in a privileged network position may be able to bypass HSTS for a limited number of specific top-level domains previously not in the HSTS preload list Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2018-4225P4MEDIUMCVSS 5.5v7.52018-06-01
CVE-2018-4225 [MEDIUM] CVE-2018-4225: iCloud for Windows 7.5 Apple Security Update: About the security content of iCloud for Windows 7.5 Product: iCloud for Windows Version: 7.5 CVE: CVE-2018-4225 Component: Security Impact: A local user may be able to modify the state of the Keychain Description: An authorization issue was addressed with improved state management.
apple
CVE-2018-4226P4MEDIUMCVSS 5.5v7.52018-06-01
CVE-2018-4226 [MEDIUM] CVE-2018-4226: iCloud for Windows 7.5 Apple Security Update: About the security content of iCloud for Windows 7.5 Product: iCloud for Windows Version: 7.5 CVE: CVE-2018-4226 Component: Security Impact: A local user may be able to view sensitive user information Description: An authorization issue was addressed with improved state management.
apple
CVE-2016-7592P4MEDIUMCVSS 4.3v6.12016-12-13
CVE-2016-7592 [MEDIUM] CVE-2016-7592: iCloud for Windows 6.1 Apple Security Update: About the security content of iCloud for Windows 6.1 Product: iCloud for Windows Version: 6.1 CVE: CVE-2016-7592 Component: WebKit Impact: Processing maliciously crafted web content may compromise user information Description: An issue existed in handling of JavaScript prompts. This was addressed through improved state management.
apple
CVE-2020-3887P4MEDIUMCVSS 4.3≥ unspecified, < iCloud for Windows 10.9.3≥ unspecified, < iCloud for Windows 7.182020-04-01
CVE-2020-3887 [MEDIUM] CVE-2020-3887: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.
nvd
CVE-2020-15358P4MEDIUMCVSS 5.5v7.212020-09-24
CVE-2020-15358 [MEDIUM] CVE-2020-15358: iCloud for Windows 7.21 Apple Security Update: About the security content of iCloud for Windows 7.21 Product: iCloud for Windows Version: 7.21 CVE: CVE-2020-15358 Component: CVE-2020-15358
apple
CVE-2016-7614P4MEDIUMCVSS 5.5v6.12016-12-13
CVE-2016-7614 [MEDIUM] CVE-2016-7614: iCloud for Windows 6.1 Apple Security Update: About the security content of iCloud for Windows 6.1 Product: iCloud for Windows Version: 6.1 CVE: CVE-2016-7614 Component: Windows Security Impact: A local user may be able to leak sensitive user information Description: The iCloud desktop client failed to clear sensitive information in memory. This issue was addressed through improved memory handling.
apple
Apple Icloud For Windows vulnerabilities | cvebase