Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pekka Oikarainen

Researcher fromSynopsys Software Integrity Group
#14541of 53,635
18.6Total CVSS
Vulnerabilities · 2
High
2
PT-2017-1773
9.3
2017-04-02
Apple · Apple Macos · CVE-2017-2420
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.12.4 **Description** The issue is related to a buffer overflow in the Bluetooth component of the operating system, which can be exploited by a remote attacker to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) using a specially crafted application. **Recommendations** For macOS versions prior to 10.12.4, update to version 10.12.4 or later to resolve the issue.
PT-2017-1352
9.3
2017-02-20
Apple · Apple Macos · CVE-2016-7596
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.12.2 **Description** The issue involves the `Bluetooth` component and allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. This is caused by a buffer overflow in the Bluetooth component, which can be exploited by a remote attacker to achieve the aforementioned effects. **Recommendations** For macOS versions prior to 10.12.2, update to version 10.12.2 or later to resolve the issue. As a temporary workaround, consider disabling the Bluetooth component until a patch is available. Restrict access to the Bluetooth functionality to minimize the risk of exploitation.