CVE-2016-1853 describes an information disclosure vulnerability in Tcl within Apple OS X before version 10.11.5, allowing remote attackers to obtain sensitive information by leveraging SSLv2 support. With a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and requires no user interaction, potentially leading to high confidentiality impact. Despite its severity, there is no known public exploit code (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.11.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.