Total
4068 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-3724 | 1 Apple | 1 Iphone Os | 2016-12-30 | 6.8 MEDIUM | N/A |
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723. | |||||
CVE-2015-3725 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.3 MEDIUM | N/A |
MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app. | |||||
CVE-2015-3723 | 1 Apple | 1 Iphone Os | 2016-12-30 | 6.8 MEDIUM | N/A |
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724. | |||||
CVE-2015-3722 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.3 MEDIUM | N/A |
Application Store in Apple iOS before 8.4 does not ensure the uniqueness of bundle IDs, which allows attackers to cause a denial of service (ID collision and launch outage) via a crafted universal provisioning profile app. | |||||
CVE-2015-3659 | 1 Apple | 3 Iphone Os, Mac Os X, Safari | 2016-12-28 | 6.8 MEDIUM | N/A |
The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site. | |||||
CVE-2015-3658 | 1 Apple | 3 Iphone Os, Mac Os X, Safari | 2016-12-28 | 6.8 MEDIUM | N/A |
The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site. | |||||
CVE-2015-3727 | 1 Apple | 3 Iphone Os, Mac Os X, Safari | 2016-12-28 | 6.8 MEDIUM | N/A |
WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site. | |||||
CVE-2015-3728 | 1 Apple | 1 Iphone Os | 2016-12-28 | 4.8 MEDIUM | N/A |
The WiFi Connectivity feature in Apple iOS before 8.4 allows remote Wi-Fi access points to trigger an automatic association, with an arbitrary security type, by operating with a recognized ESSID within an 802.11 network's coverage area. | |||||
CVE-2015-6974 | 1 Apple | 3 Iphone Os, Mac Os X, Watchos | 2016-12-24 | 9.3 HIGH | N/A |
IOHIDFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | |||||
CVE-2015-6995 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-24 | 6.8 MEDIUM | N/A |
The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app. | |||||
CVE-2015-3776 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-24 | 9.3 HIGH | N/A |
IOKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption and application crash) via a malformed plist. | |||||
CVE-2015-5775 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-24 | 7.5 HIGH | N/A |
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5756. | |||||
CVE-2015-3759 | 1 Apple | 1 Iphone Os | 2016-12-24 | 4.6 MEDIUM | N/A |
Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink. | |||||
CVE-2015-5926 | 1 Apple | 3 Iphone Os, Mac Os X, Watchos | 2016-12-24 | 6.8 MEDIUM | N/A |
The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925. | |||||
CVE-2015-7022 | 1 Apple | 1 Iphone Os | 2016-12-24 | 4.3 MEDIUM | N/A |
The Telephony subsystem in Apple iOS before 9.1 allows attackers to obtain sensitive call-status information via a crafted app. | |||||
CVE-2015-7010 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-24 | 6.8 MEDIUM | N/A |
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7018. | |||||
CVE-2015-5759 | 1 Apple | 1 Iphone Os | 2016-12-24 | 5.0 MEDIUM | N/A |
WebKit in Apple iOS before 8.4.1 allows remote attackers to spoof clicks via a crafted web site that leverages tap events. | |||||
CVE-2015-5942 | 1 Apple | 3 Iphone Os, Mac Os X, Watchos | 2016-12-24 | 6.8 MEDIUM | N/A |
FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5927. | |||||
CVE-2015-5929 | 1 Apple | 3 Iphone Os, Itunes, Safari | 2016-12-24 | 6.8 MEDIUM | N/A |
WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5. | |||||
CVE-2015-5758 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-24 | 6.8 MEDIUM | N/A |
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image. |