VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2015-1095Apr 10, 2015
    risk 0.00cvss epss 0.00

    IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HID device.

  • CVE-2015-1093Apr 10, 2015
    risk 0.00cvss epss 0.03

    FontParser in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.

  • CVE-2015-1091Apr 10, 2015
    risk 0.00cvss epss 0.02

    The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle request headers during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

  • CVE-2015-1089Apr 10, 2015
    risk 0.00cvss epss 0.02

    CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

  • CVE-2015-1088Apr 10, 2015
    risk 0.00cvss epss 0.02

    CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code via a crafted web site.

  • CVE-2015-1069Mar 18, 2015
    risk 0.00cvss epss 0.03

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed…

  • CVE-2015-1066Mar 12, 2015
    risk 0.00cvss epss 0.03

    Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

  • CVE-2015-1065Mar 12, 2015
    risk 0.00cvss epss 0.01

    Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.

  • CVE-2015-1061Mar 12, 2015
    risk 0.00cvss epss 0.04

    IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.

  • CVE-2015-0228Mar 8, 2015
    risk 0.00cvss epss 0.19

    The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade…

  • CVE-2015-1546Feb 12, 2015
    risk 0.00cvss epss 0.03

    Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.

  • CVE-2014-8839Jan 30, 2015
    risk 0.00cvss epss 0.02

    Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's…

  • CVE-2014-8838Jan 30, 2015
    risk 0.00cvss epss 0.01

    The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the Gatekeeper protection mechanism by leveraging access to a revoked Developer ID certificate for signing a crafted app.

  • CVE-2014-8837Jan 30, 2015
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arbitrary code in a privileged context via a crafted app.

  • CVE-2014-8836Jan 30, 2015
    risk 0.00cvss epss 0.03

    The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (arbitrary-size bzero of kernel memory) via a crafted app.

  • CVE-2014-8834Jan 30, 2015
    risk 0.00cvss epss 0.00

    UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, which allows local users to obtain sensitive information by reading a file.

  • CVE-2014-8833Jan 30, 2015
    risk 0.00cvss epss 0.00

    SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cache, which allows local users to read search results associated with other users' protected files via a Spotlight query.

  • CVE-2014-8832Jan 30, 2015
    risk 0.00cvss epss 0.00

    The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, which allows local users to obtain sensitive information by reading from this drive.

  • CVE-2014-8831Jan 30, 2015
    risk 0.00cvss epss 0.01

    security_taskgate in Apple OS X before 10.10.2 allows attackers to read group-ACL-restricted keychain items of arbitrary apps via a crafted app with a signature from a (1) self-signed certificate or (2) Developer ID certificate.

  • CVE-2014-8830Jan 30, 2015
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted accessor element in a Collada file.

Page 116 of 163