Apple Icloud For Windows vulnerabilities
445 known vulnerabilities affecting apple/icloud_for_windows.
Total CVEs
445
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
10
Severity breakdown
CRITICAL20HIGH346MEDIUM77LOW2
Vulnerabilities
Page 22 of 23
CVE-2016-4743P4HIGHCVSS 7.1v6.12016-12-13
CVE-2016-4743 [HIGH] CVE-2016-4743: iCloud for Windows 6.1
Apple Security Update: About the security content of iCloud for Windows 6.1
Product: iCloud for Windows
Version: 6.1
CVE: CVE-2016-4743
Component: WebKit
Impact: Processing maliciously crafted web content may result in the disclosure of process memory
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-1836P4MEDIUMCVSS 5.5v5.2.12016-07-18
CVE-2016-1836 [MEDIUM] CVE-2016-1836: iCloud for Windows 5.2.1
Apple Security Update: About the security content of iCloud for Windows 5.2.1
Product: iCloud for Windows
Version: 5.2.1
CVE: CVE-2016-1836
Component: About Apple security updates
Impact: Multiple vulnerabilities in libxml2
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2018-4309P4MEDIUMCVSS 6.1v7.72018-10-08
CVE-2018-4309 [MEDIUM] CVE-2018-4309: iCloud for Windows 7.7
Apple Security Update: About the security content of iCloud for Windows 7.7
Product: iCloud for Windows
Version: 7.7
CVE: CVE-2018-4309
Component: WebKit
Impact: A malicious website may be able to execute scripts in the context of another website
Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4345P4MEDIUMCVSS 6.1v7.72018-10-08
CVE-2018-4345 [MEDIUM] CVE-2018-4345: iCloud for Windows 7.7
Apple Security Update: About the security content of iCloud for Windows 7.7
Product: iCloud for Windows
Version: 7.7
CVE: CVE-2018-4345
Component: WebKit
Impact: A malicious website may exfiltrate image data cross-origin
Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4377P4MEDIUMCVSS 6.1v7.82018-10-30
CVE-2018-4377 [MEDIUM] CVE-2018-4377: iCloud for Windows 7.8
Apple Security Update: About the security content of iCloud for Windows 7.8
Product: iCloud for Windows
Version: 7.8
CVE: CVE-2018-4377
Component: Safari Reader
Impact: Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting
Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4293P4MEDIUMCVSS 5.3v7.62018-07-09
CVE-2018-4293 [MEDIUM] CVE-2018-4293: iCloud for Windows 7.6
Apple Security Update: About the security content of iCloud for Windows 7.6
Product: iCloud for Windows
Version: 7.6
CVE: CVE-2018-4293
Component: CFNetwork
Impact: Cookies may unexpectedly persist in Safari
Description: A cookie management issue was addressed with improved checks.
apple
CVE-2019-8764P4MEDIUMCVSS 6.1v7.142019-10-07
CVE-2019-8764 [MEDIUM] CVE-2019-8764: iCloud for Windows 7.14
Apple Security Update: About the security content of iCloud for Windows 7.14
Product: iCloud for Windows
Version: 7.14
CVE: CVE-2019-8764
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue was addressed with improved state management.
apple
CVE-2017-7109P4MEDIUMCVSS 6.1v7.02017-09-25
CVE-2017-7109 [MEDIUM] CVE-2017-7109: iCloud for Windows 7.0
Apple Security Update: About the security content of iCloud for Windows 7.0
Product: iCloud for Windows
Version: 7.0
CVE: CVE-2017-7109
Component: WebKit
Impact: Processing maliciously crafted web content may lead to a cross site scripting attack
Description: Application Cache policy may be unexpectedly applied.
apple
CVE-2017-13831P4HIGHCVSS 7.1v7.02017-09-25
CVE-2017-13831 [HIGH] CVE-2017-13831: iCloud for Windows 7.0
Apple Security Update: About the security content of iCloud for Windows 7.0
Product: iCloud for Windows
Version: 7.0
CVE: CVE-2017-13831
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: An information disclosure issue existed in the processing of disk images. This issue was addressed through improved memory management.
apple
CVE-2019-8582P4MEDIUMCVSS 5.5v7.122019-05-28
CVE-2019-8582 [MEDIUM] CVE-2019-8582: iCloud for Windows 7.12
Apple Security Update: About the security content of iCloud for Windows 7.12
Product: iCloud for Windows
Version: 7.12
CVE: CVE-2019-8582
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2018-4224P4MEDIUMCVSS 5.5v7.52018-06-01
CVE-2018-4224 [MEDIUM] CVE-2018-4224: iCloud for Windows 7.5
Apple Security Update: About the security content of iCloud for Windows 7.5
Product: iCloud for Windows
Version: 7.5
CVE: CVE-2018-4224
Component: Security
Impact: A local user may be able to read a persistent device identifier
Description: An authorization issue was addressed with improved state management.
apple
CVE-2018-4232P4MEDIUMCVSS 4.3v7.52018-06-01
CVE-2018-4232 [MEDIUM] CVE-2018-4232: iCloud for Windows 7.5
Apple Security Update: About the security content of iCloud for Windows 7.5
Product: iCloud for Windows
Version: 7.5
CVE: CVE-2018-4232
Component: WebKit
Impact: Visiting a maliciously crafted website may lead to cookies being overwritten
Description: A permissions issue existed in the handling of web browser cookies. This issue was addressed with improved restrictions.
apple
CVE-2020-3885P4MEDIUMCVSS 4.3≥ unspecified, < iCloud for Windows 10.9.3≥ unspecified, < iCloud for Windows 7.182020-04-01
CVE-2020-3885 [MEDIUM] CWE-670 CVE-2020-3885: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.
nvd
CVE-2019-8834P4MEDIUMCVSS 4.3v10.92019-12-11
CVE-2019-8834 [MEDIUM] CVE-2019-8834: iCloud for Windows 10.9
Apple Security Update: About the security content of iCloud for Windows 10.9
Product: iCloud for Windows
Version: 10.9
CVE: CVE-2019-8834
Component: CFNetwork
Impact: An attacker in a privileged network position may be able to bypass HSTS for a limited number of specific top-level domains previously not in the HSTS preload list
Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2018-4225P4MEDIUMCVSS 5.5v7.52018-06-01
CVE-2018-4225 [MEDIUM] CVE-2018-4225: iCloud for Windows 7.5
Apple Security Update: About the security content of iCloud for Windows 7.5
Product: iCloud for Windows
Version: 7.5
CVE: CVE-2018-4225
Component: Security
Impact: A local user may be able to modify the state of the Keychain
Description: An authorization issue was addressed with improved state management.
apple
CVE-2018-4226P4MEDIUMCVSS 5.5v7.52018-06-01
CVE-2018-4226 [MEDIUM] CVE-2018-4226: iCloud for Windows 7.5
Apple Security Update: About the security content of iCloud for Windows 7.5
Product: iCloud for Windows
Version: 7.5
CVE: CVE-2018-4226
Component: Security
Impact: A local user may be able to view sensitive user information
Description: An authorization issue was addressed with improved state management.
apple
CVE-2016-7592P4MEDIUMCVSS 4.3v6.12016-12-13
CVE-2016-7592 [MEDIUM] CVE-2016-7592: iCloud for Windows 6.1
Apple Security Update: About the security content of iCloud for Windows 6.1
Product: iCloud for Windows
Version: 6.1
CVE: CVE-2016-7592
Component: WebKit
Impact: Processing maliciously crafted web content may compromise user information
Description: An issue existed in handling of JavaScript prompts. This was addressed through improved state management.
apple
CVE-2020-3887P4MEDIUMCVSS 4.3≥ unspecified, < iCloud for Windows 10.9.3≥ unspecified, < iCloud for Windows 7.182020-04-01
CVE-2020-3887 [MEDIUM] CVE-2020-3887: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.
nvd
CVE-2020-15358P4MEDIUMCVSS 5.5v7.212020-09-24
CVE-2020-15358 [MEDIUM] CVE-2020-15358: iCloud for Windows 7.21
Apple Security Update: About the security content of iCloud for Windows 7.21
Product: iCloud for Windows
Version: 7.21
CVE: CVE-2020-15358
Component: CVE-2020-15358
apple
CVE-2016-7614P4MEDIUMCVSS 5.5v6.12016-12-13
CVE-2016-7614 [MEDIUM] CVE-2016-7614: iCloud for Windows 6.1
Apple Security Update: About the security content of iCloud for Windows 6.1
Product: iCloud for Windows
Version: 6.1
CVE: CVE-2016-7614
Component: Windows Security
Impact: A local user may be able to leak sensitive user information
Description: The iCloud desktop client failed to clear sensitive information in memory. This issue was addressed through improved memory handling.
apple