Apple Macos Sierra vulnerabilities
81 known vulnerabilities affecting apple/macos_sierra.
Total CVEs
81
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH44MEDIUM16LOW5
Vulnerabilities
Page 3 of 5
CVE-2016-4699P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4699 [HIGH] CVE-2016-4699: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4699
Component: AppleUUC
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved input validation.
apple
CVE-2016-4716P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4716 [HIGH] CVE-2016-4716: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4716
Component: DiskArbitration
Impact: A local user may be able to execute arbitrary code with system privileges
Description: An access issue existed in diskutil. This issue was addressed through improved permissions checking.
apple
CVE-2016-5131P3HIGHCVSS 8.8v10.122016-09-20
CVE-2016-5131 [HIGH] CVE-2016-5131: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-5131
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-4777P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4777 [HIGH] CVE-2016-4777: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4777
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: An untrusted pointer dereference was addressed by removing the affected code.
apple
CVE-2016-4772P3HIGHCVSS 7.5v10.122016-09-20
CVE-2016-4772 [HIGH] CVE-2016-4772: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4772
Component: Kernel
Impact: A remote attacker may be able to cause a denial of service
Description: A lock handling issue was addressed through improved lock handling.
apple
CVE-2016-4709P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4709 [HIGH] CVE-2016-4709: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4709
Component: WindowServer
Impact: A local user may be able to gain root privileges
Description: A type confusion issue was addressed through improved memory handling.
apple
CVE-2016-4710P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4710 [HIGH] CVE-2016-4710: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4710
Component: WindowServer
Impact: A local user may be able to gain root privileges
Description: A type confusion issue was addressed through improved memory handling.
apple
CVE-2016-4775P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4775 [HIGH] CVE-2016-4775: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4775
Component: Kernel
Impact: A local user may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-4725P3HIGHCVSS 8.1v10.122016-09-20
CVE-2016-4725 [HIGH] CVE-2016-4725: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4725
Component: IOAcceleratorFamily
Impact: Processing maliciously crafted web content may result in the disclosure of process memory
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-4750P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4750 [HIGH] CVE-2016-4750: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4750
Component: S2 Camera
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-4723P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4723 [HIGH] CVE-2016-4723: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4723
Component: Intel Graphics Driver
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-4727P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4727 [HIGH] CVE-2016-4727: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4727
Component: IOThunderboltFamily
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-4703P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4703 [HIGH] CVE-2016-4703: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4703
Component: Bluetooth
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2017-2358P3HIGHCVSS 7.8v10.12.32017-01-23
CVE-2017-2358 [HIGH] CVE-2017-2358: macOS Sierra 10.12.3
Apple Security Update: About the security content of macOS Sierra 10.12.3
Product: macOS Sierra
Version: 10.12.3
CVE: CVE-2017-2358
Component: Graphics Drivers
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-4697P3HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4697 [HIGH] CVE-2016-4697: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4697
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-4724P4HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4724 [HIGH] CVE-2016-4724: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4724
Component: IOAcceleratorFamily
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2016-4696P4HIGHCVSS 7.8v10.122016-09-20
CVE-2016-4696 [HIGH] CVE-2016-4696: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4696
Component: AppleEFIRuntime
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2016-4708P4MEDIUMCVSS 6.5v10.122016-09-20
CVE-2016-4708 [MEDIUM] CVE-2016-4708: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4708
Component: CFNetwork
Impact: Processing maliciously crafted web content may compromise user information
Description: An input validation issue existed in the parsing of the set-cookie header. This issue was addressed through improved validation checking.
apple
CVE-2016-4718P4MEDIUMCVSS 6.5v10.122016-09-20
CVE-2016-4718 [MEDIUM] CVE-2016-4718: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4718
Component: FontParser
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: A buffer overflow existed in the handling of font files. This issue was addressed through improved bounds checking.
apple
CVE-2016-4745P4MEDIUMCVSS 5.3v10.122016-09-20
CVE-2016-4745 [MEDIUM] CVE-2016-4745: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4745
Component: Kerberos v5 PAM module
Impact: A remote attacker may determine the existence of user accounts
Description: A timing side channel allowed an attacker to determine the existence of user accounts on a system. This issue was addressed by introducing constant time checks.
apple