PatchSiren

Apple CVE debriefs · Page 18

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Apple CVE published 2017-02-20

CVE-2016-4683

CVE-2016-4683 is an Apple ImageIO vulnerability affecting macOS before 10.12.1. According to the NVD record, a crafted SGI file can trigger out-of-bounds memory access and application crash, with the potential for arbitrary code execution. The weakness is classified as CWE-119, and NVD assigns it a high CVSS 3.0 score of 7.8. From a defensive perspective, this is a file-parsing memory-safety issue that ma [truncated]

HIGH Apple CVE published 2017-02-20

CVE-2016-4682

CVE-2016-4682 is an Apple ImageIO vulnerability affecting macOS systems in the versions identified by the vendor and NVD. A crafted SGI file could trigger an out-of-bounds read, allowing sensitive information disclosure or an application crash. The issue was publicly recorded on 2017-02-20; the later 2026 modified date is an update to the record, not the original disclosure date.

HIGH Apple CVE published 2017-02-20

CVE-2016-4681

CVE-2016-4681 is a High-severity Apple vulnerability in macOS Core Image affecting versions before 10.12.1. A crafted JPEG can trigger memory corruption, leading to arbitrary code execution or a crash/denial of service. NVD rates the issue as requiring user interaction, so systems that open untrusted images should be patched promptly.

MEDIUM Apple CVE published 2017-02-20

CVE-2016-4680

CVE-2016-4680 is a medium-severity Apple kernel information disclosure issue. According to the CVE and NVD metadata, a crafted app could obtain sensitive information from kernel memory on affected iOS, tvOS, and watchOS devices. Apple’s affected-version thresholds indicate the issue was addressed in iOS 10.1, tvOS 10.0.1, and watchOS 3.1. Because the impact is confidentiality-only, the main concern is exp [truncated]

MEDIUM Apple CVE published 2017-02-20

CVE-2016-4679

CVE-2016-4679 is an Apple libarchive issue affecting older versions of iOS, macOS, tvOS, and watchOS. A crafted archive containing a symlink could enable arbitrary file writes, which is why Apple issued platform updates to address the flaw.

HIGH Apple CVE published 2017-02-20

CVE-2016-4678

CVE-2016-4678 is a high-severity local vulnerability in macOS before 10.12.1 affecting the AppleSMC component. According to NVD, local users could gain privileges or trigger a denial of service through unspecified vectors, and the weakness is classified as a NULL pointer dereference (CWE-476). The NVD record shows a local attack path with low attack complexity and no user interaction, which makes this esp [truncated]

HIGH Apple CVE published 2017-02-20

CVE-2016-4677

CVE-2016-4677 is a high-severity Apple WebKit memory corruption issue that could be triggered through a crafted website. According to the supplied CVE metadata, it affects iOS before 10.1, Safari before 10.0.1, and tvOS before 10.0.1. The impact is serious because a remote attacker could potentially execute arbitrary code or cause a denial of service by convincing a user to visit a malicious page.

HIGH Apple CVE published 2017-02-20

CVE-2016-4675

CVE-2016-4675 is an Apple vulnerability in the libxpc component that can let a crafted app execute arbitrary code in a privileged context. The CVE record lists affected releases before iOS 10.1, macOS 10.12.1, tvOS 10.0.1, and watchOS 3.1. Because the attack requires local app interaction and user involvement, it is not a remote-only issue, but the impact is high due to privileged code execution.

HIGH Apple CVE published 2017-02-20

CVE-2016-4674

CVE-2016-4674 is a high-severity macOS flaw in Apple’s ATS component affecting versions before 10.12.1. According to the NVD record, the issue can let a local user gain privileges or cause a denial of service through memory corruption and application crash. Apple’s advisory and the NVD entry both point to a local-attack scenario with no user interaction required, making this most relevant on systems where [truncated]

HIGH Apple CVE published 2017-02-20

CVE-2016-4673

CVE-2016-4673 is a memory-corruption issue in Apple’s CoreGraphics component affecting iOS before 10.1, macOS before 10.12.1, tvOS before 10.0.1, and watchOS before 3.1. The issue can be triggered through a crafted JPEG file and may result in arbitrary code execution or a denial of service via application crash. NVD classifies the weakness as CWE-119 and rates the issue HIGH.

HIGH Apple CVE published 2017-02-20

CVE-2016-4671

CVE-2016-4671 describes a memory-corruption issue in Apple’s ImageIO component on macOS. The problem is associated with crafted PDF content and is described as allowing remote attackers to execute arbitrary code or cause a denial of service through an out-of-bounds write and application crash. NVD lists affected macOS versions through 10.12.0, matching the narrative that systems before 10.12.1 are impacted.

LOW Apple CVE published 2017-02-20

CVE-2016-4670

CVE-2016-4670 is a low-severity Apple information-disclosure issue in the Security component. According to the NVD and Apple advisories, a local user could read a log and learn the length of arbitrary passwords. The issue was fixed in iOS 10.1 and macOS 10.12.1. This does not indicate direct password disclosure or remote compromise, but it can still aid local reconnaissance and account-targeting efforts.

HIGH Apple CVE published 2017-02-20

CVE-2016-4669

CVE-2016-4669 describes an Apple kernel issue that can let a local user reach privileged code execution or trigger a system crash. Affected releases include iOS before 10.1, macOS before 10.12.1, tvOS before 10.0.1, and watchOS before 3.1. Because the attack requires local access and can impact kernel integrity, patching affected Apple systems should be treated as a high-priority defensive task.

HIGH Apple CVE published 2017-02-20

CVE-2016-4667

CVE-2016-4667 is an Apple macOS vulnerability in the ATS component affecting versions before 10.12.1. According to NVD, a crafted font can trigger memory corruption, which may lead to remote code execution or a denial of service through an application crash. The issue was publicly disclosed on 2017-02-20 and is rated HIGH with a CVSS 3.0 score of 8.8.

HIGH Apple CVE published 2017-02-20

CVE-2016-4666

CVE-2016-4666 is a high-severity Apple WebKit memory-corruption issue that could let a remote attacker use a crafted website to execute code or crash the browser/process. NVD lists iOS versions before 10.1, Safari before 10.0.1, and tvOS before 10.0.1 as affected.

LOW Apple CVE published 2017-02-20

CVE-2016-4665

CVE-2016-4665 is a low-severity information disclosure issue in Apple’s Sandbox Profiles component. According to the supplied record, a crafted app could read audio-recording metadata on affected Apple mobile and wearable OS versions. The vulnerability was published on 2017-02-20 and later modified in the NVD record on 2026-05-13, which is record maintenance rather than the original disclosure date.

LOW Apple CVE published 2017-02-20

CVE-2016-4664

CVE-2016-4664 is a low-severity Apple information-disclosure issue in the Sandbox Profiles component. A crafted app could read photo-directory metadata on affected devices, exposing limited information rather than allowing code execution or direct file modification. The CVE was published on 2017-02-20, and the supplied record ties it to Apple advisories for iOS, tvOS, and watchOS.

MEDIUM Apple CVE published 2017-02-20

CVE-2016-4663

CVE-2016-4663 is a medium-severity macOS issue in the NVIDIA Graphics Drivers component. On affected systems running macOS before 10.12.1, a crafted app can trigger memory corruption and crash the system, resulting in denial of service. The public record does not indicate impact beyond availability.

HIGH Apple CVE published 2017-02-20

CVE-2016-4662

CVE-2016-4662 is a high-severity Apple macOS issue affecting systems before 10.12.1. The vulnerable AppleGraphicsControl component can be triggered by a crafted app and may allow arbitrary code execution in a privileged context or cause a denial of service through memory corruption. Apple and NVD list this as a High-severity issue with local access and user interaction required.

MEDIUM Apple CVE published 2017-02-20

CVE-2016-4661

CVE-2016-4661 affects macOS before 10.12.1. According to the NVD and Apple references, the issue is in the NTFS component, which misparses disk images. An attacker who can get a crafted app to be opened or processed on the affected system may be able to trigger a denial of service. The CVSS v3 vector indicates local access with user interaction required and impact limited to availability.

HIGH Apple CVE published 2017-02-20

CVE-2016-4660

CVE-2016-4660 is an Apple FontParser vulnerability affecting multiple Apple operating systems. A crafted font can trigger an out-of-bounds read, which may disclose sensitive information or cause an application crash and denial of service. The CVE is publicly disclosed and rated high severity in the supplied record, with network attack potential but requiring user interaction.

HIGH Apple CVE published 2017-02-20

CVE-2016-4617

CVE-2016-4617 is a local macOS sandbox escape issue in Apple’s libxpc component. According to NVD, it affects macOS versions up to 10.11.6 and is associated with launchctl process spawning. The vulnerability is rated 8.8 HIGH, with low attack complexity, low privileges required, no user interaction, and a changed scope impact profile.

MEDIUM Apple CVE published 2017-02-20

CVE-2016-4613

CVE-2016-4613 is a medium-severity Apple WebKit information-disclosure issue affecting multiple Apple products. According to the NVD record, a remote attacker could use a crafted website to obtain sensitive information from affected installations. The vulnerability is listed for Safari, iCloud, iTunes, and tvOS/Apple TV versions prior to the fixed releases noted in the CVE data.