Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Happilycoded

Pesquisador deTrend Micro's Zero Day Initiative (ZDI)
#18475de 53,619
14.6CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2016-1566
7.8
2016-03-24
Apple · Os X · CVE-2016-1738
**Name of the Vulnerable Software and Affected Versions** Apple OS X versions prior to 10.11.4 **Description** The issue is related to the dyld component in the operating system, which is connected to errors in security settings. It allows an attacker to bypass a code-signing protection mechanism via a modified app. This can be exploited by a local attacker. **Recommendations** For Apple OS X versions prior to 10.11.4, update to version 10.11.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of modified apps to minimize the risk of exploitation.
PT-2016-1567
6.8
2016-03-24
Apple · Os X · CVE-2016-1737
**Name of the Vulnerable Software and Affected Versions** Apple OS X versions prior to 10.11.4 **Description** The issue is caused by a buffer overflow in the Carbon component of the Mac OS X operating system. Exploitation of this issue may allow a remote attacker to execute arbitrary code or cause a denial of service (memory corruption) by using a specially crafted .dfont file. **Recommendations** For Apple OS X versions prior to 10.11.4, update to version 10.11.4 or later to resolve the issue. As a temporary workaround, consider restricting access to .dfont files to minimize the risk of exploitation.