Apple Macos Sierra vulnerabilities
81 known vulnerabilities affecting apple/macos_sierra.
Total CVEs
81
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH44MEDIUM16LOW5
Vulnerabilities
Page 4 of 5
CVE-2016-4713P4MEDIUMCVSS 5.3v10.122016-09-20
CVE-2016-4713 [MEDIUM] CVE-2016-4713: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4713
Component: CoreDisplay
Impact: A user with screen sharing access may be able to view another user's screen
Description: A session management issue existed in the handling of screen sharing sessions. This issue was addressed through improved session tracking.
apple
CVE-2016-6292P4MEDIUMCVSS 6.5v10.122016-09-20
CVE-2016-6292 [MEDIUM] CVE-2016-6292: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-6292
Component: CVE-2016-6292
apple
CVE-2016-4776P4HIGHCVSS 7.1v10.122016-09-20
CVE-2016-4776 [HIGH] CVE-2016-4776: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4776
Component: Kernel
Impact: An application may be able to determine kernel memory layout
Description: Multiple out-of-bounds read issues existed that led to the disclosure of kernel memory. These were addressed through improved input validation.
apple
CVE-2016-4773P4HIGHCVSS 7.1v10.122016-09-20
CVE-2016-4773 [HIGH] CVE-2016-4773: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4773
Component: Kernel
Impact: An application may be able to determine kernel memory layout
Description: Multiple out-of-bounds read issues existed that led to the disclosure of kernel memory. These were addressed through improved input validation.
apple
CVE-2016-4774P4HIGHCVSS 7.1v10.122016-09-20
CVE-2016-4774 [HIGH] CVE-2016-4774: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4774
Component: Kernel
Impact: An application may be able to determine kernel memory layout
Description: Multiple out-of-bounds read issues existed that led to the disclosure of kernel memory. These were addressed through improved input validation.
apple
CVE-2016-7580P4MEDIUMCVSS 6.5v10.122016-09-20
CVE-2016-7580 [MEDIUM] CVE-2016-7580: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-7580
Component: Mail
Impact: A malicious website may be able to cause a denial-of-service
Description: A denial of service issue was addressed through improved URL handling.
apple
CVE-2016-4722P4MEDIUMCVSS 5.9v10.122016-09-20
CVE-2016-4722 [MEDIUM] CVE-2016-4722: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4722
Component: IDS - Connectivity
Impact: An attacker in a privileged network position may be able to cause a denial of service
Description: A spoofing issue existed in the handling of Call Relay. This issue was addressed through improved input validation.
apple
CVE-2016-4682P4HIGHCVSS 7.1v10.122016-09-20
CVE-2016-4682 [HIGH] CVE-2016-4682: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4682
Component: ImageIO
Impact: Processing maliciously crafted image may result in the disclosure of process memory
Description: An out-of-bounds read issue existed in the SGI image parsing. This issue was addressed through improved bounds checking.
apple
CVE-2016-4771P4MEDIUMCVSS 5.5v10.122016-09-20
CVE-2016-4771 [MEDIUM] CVE-2016-4771: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4771
Component: Kernel
Impact: A local application may be able to access restricted files
Description: A parsing issue in the handling of directory paths was addressed through improved path validation.
apple
CVE-2016-4742P4MEDIUMCVSS 5.5v10.122016-09-20
CVE-2016-4742 [MEDIUM] CVE-2016-4742: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4742
Component: NSSecureTextField
Impact: A malicious application may be able to leak a user's credentials
Description: A state management issue existed in NSSecureTextField, which failed to enable Secure Input. This issue was addressed through improved window management.
apple
CVE-2016-4748P4MEDIUMCVSS 5.3v10.122016-09-20
CVE-2016-4748 [MEDIUM] CVE-2016-4748: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4748
Component: Perl
Impact: A local user may be able to bypass the taint protection mechanism
Description: An issue existed in the parsing of environment variables. This issue was addressed through improved validation of environment variables.
apple
CVE-2016-4752P4MEDIUMCVSS 5.5v10.122016-09-20
CVE-2016-4752 [MEDIUM] CVE-2016-4752: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4752
Component: Security
Impact: An application using SecKeyDeriveFromPassword may leak memory
Description: A resource management issue existed in the handling of key derivation. This issue was addressed by adding CF_RETURNS_RETAINED to SecKeyDeriveFromPassword.
apple
CVE-2016-4755P4MEDIUMCVSS 5.5v10.122016-09-20
CVE-2016-4755 [MEDIUM] CVE-2016-4755: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4755
Component: Terminal
Impact: A local user may be able to leak sensitive user information
Description: A permissions issue existed in .bash_history and .bash_session. This issue was addressed through improved access restrictions.
apple
CVE-2016-4701P4MEDIUMCVSS 6.2v10.122016-09-20
CVE-2016-4701 [MEDIUM] CVE-2016-4701: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4701
Component: Application Firewall
Impact: A local user may be able to cause a denial of service
Description: A validation issue existed in the handling of firewall prompts. This issue was addressed through improved validation of SO_EXECPATH.
apple
CVE-2016-4706P4MEDIUMCVSS 5.5v10.122016-09-20
CVE-2016-4706 [MEDIUM] CVE-2016-4706: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4706
Component: Bluetooth
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-4707P4MEDIUMCVSS 4.0v10.122016-09-20
CVE-2016-4707 [MEDIUM] CVE-2016-4707: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4707
Component: CFNetwork
Impact: A local user may be able to discover websites a user has visited
Description: An issue existed in Local Storage deletion. This issue was addressed through improved Local Storage cleanup.
apple
CVE-2016-4739P4LOWCVSS 3.7v10.122016-09-20
CVE-2016-4739 [LOW] CVE-2016-4739: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4739
Component: Mail
Impact: A malicious website may be able to cause a denial-of-service
Description: A denial of service issue was addressed through improved URL handling.
apple
CVE-2016-4715P4LOWCVSS 3.3v10.122016-09-20
CVE-2016-4715 [LOW] CVE-2016-4715: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4715
Component: Date & Time Pref Pane
Impact: A malicious application may be able to determine a user's current location
Description: An issue existed in the handling of the .GlobalPreferences file. This was addressed though improved validation.
apple
CVE-2017-2357P4LOWCVSS 3.3v10.12.32017-01-23
CVE-2017-2357 [LOW] CVE-2017-2357: macOS Sierra 10.12.3
Apple Security Update: About the security content of macOS Sierra 10.12.3
Product: macOS Sierra
Version: 10.12.3
CVE: CVE-2017-2357
Component: IOAudioFamily
Impact: An application may be able to determine kernel memory layout
Description: An uninitialized memory issue was addressed through improved memory management.
apple
CVE-2017-2383P4LOWCVSS 3.1v10.12.32017-01-23
CVE-2017-2383 [LOW] CVE-2017-2383: macOS Sierra 10.12.3
Apple Security Update: About the security content of macOS Sierra 10.12.3
Product: macOS Sierra
Version: 10.12.3
CVE: CVE-2017-2383
Component: APNs Server
Impact: An attacker in a privileged network position can track a user's activity
Description: A client certificate was sent in plaintext. This issue was addressed through improved certificate handling.
apple