VYPR

iOS

by Apple Inc.

CVEs (3,711)

  • CVE-2015-5847Sep 18, 2015
    risk 0.00cvss —epss 0.00

    The Disk Images component in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

  • CVE-2015-5846Sep 18, 2015
    risk 0.00cvss —epss 0.03

    IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5844 and CVE-2015-5845.

  • CVE-2015-5845Sep 18, 2015
    risk 0.00cvss —epss 0.03

    IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5844 and CVE-2015-5846.

  • CVE-2015-5844Sep 18, 2015
    risk 0.00cvss —epss 0.03

    IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5845 and CVE-2015-5846.

  • CVE-2015-5843Sep 18, 2015
    risk 0.00cvss —epss 0.00

    IOMobileFrameBuffer in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

  • CVE-2015-5842Sep 18, 2015
    risk 0.00cvss —epss 0.00

    XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.

  • CVE-2015-5841Sep 18, 2015
    risk 0.00cvss —epss 0.02

    The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.

  • CVE-2015-5840Sep 18, 2015
    risk 0.00cvss —epss 0.02

    The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial of service (overflow fault and app crash) via crafted data.

  • CVE-2015-5839Sep 18, 2015
    risk 0.00cvss —epss 0.02

    dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app that places a crafted signature in an executable file.

  • CVE-2015-5838Sep 18, 2015
    risk 0.00cvss —epss 0.01

    SpringBoard in Apple iOS before 9 does not properly restrict access to privileged API calls, which allows attackers to spoof the dialog windows of an arbitrary app via a crafted app.

  • CVE-2015-5837Sep 18, 2015
    risk 0.00cvss —epss 0.01

    PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app.

  • CVE-2015-5835Sep 18, 2015
    risk 0.00cvss —epss 0.01

    Apple iOS before 9 allows attackers to obtain sensitive information about inter-app communication via a crafted app that conducts an interception attack involving an unspecified URL scheme.

  • CVE-2015-5834Sep 18, 2015
    risk 0.00cvss —epss 0.01

    IOAcceleratorFamily in Apple iOS before 9 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

  • CVE-2015-5832Sep 18, 2015
    risk 0.00cvss —epss 0.00

    The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from the keychain upon a signout action, which might allow physically proximate attackers to obtain sensitive information via unspecified vectors.

  • CVE-2015-5831Sep 18, 2015
    risk 0.00cvss —epss 0.02

    NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sensitive memory-layout information via a crafted app.

  • CVE-2015-5829Sep 18, 2015
    risk 0.00cvss —epss 0.03

    Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file.

  • CVE-2015-5827Sep 18, 2015
    risk 0.00cvss —epss 0.02

    WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) custom event, (2) message event, or (3) pop state event.

  • CVE-2015-5826Sep 18, 2015
    risk 0.00cvss —epss 0.02

    WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

  • CVE-2015-5825Sep 18, 2015
    risk 0.00cvss —epss 0.02

    WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.

  • CVE-2015-5824Sep 18, 2015
    risk 0.00cvss —epss 0.00

    The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted…

Page 162 of 186