VYPR

OS X

by Apple Inc.

CVEs (553)

  • CVE-2016-1796LowMay 20, 2016
    risk 0.22cvss 3.3epss 0.02

    Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app.

  • CVE-2016-1791LowMay 20, 2016
    risk 0.22cvss 3.3epss 0.01

    The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

  • CVE-2016-1758LowMar 24, 2016
    risk 0.22cvss 3.3epss 0.01

    The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app.

  • CVE-2016-1748LowMar 24, 2016
    risk 0.22cvss 3.3epss 0.02

    IOHIDFamily in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

  • CVE-2016-4645LowJul 22, 2016
    risk 0.21cvss 3.3epss 0.00

    CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2016-1862LowJun 19, 2016
    risk 0.21cvss 3.3epss 0.01

    Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.

  • CVE-2016-1860LowJun 19, 2016
    risk 0.21cvss 3.3epss 0.01

    Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.

  • CVE-2016-1773LowMar 24, 2016
    risk 0.21cvss 3.3epss 0.00

    The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.

  • CVE-2015-3783Aug 16, 2015
    risk 0.06cvss epss 0.36

    SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

  • CVE-2014-4492Jan 30, 2015
    risk 0.05cvss epss 0.20

    libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as…

  • CVE-2015-7112Dec 11, 2015
    risk 0.04cvss epss 0.09

    The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than…

  • CVE-2015-6996Oct 23, 2015
    risk 0.04cvss epss 0.07

    IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

  • CVE-2015-6995Oct 23, 2015
    risk 0.04cvss epss 0.06

    The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

  • CVE-2015-5754Aug 17, 2015
    risk 0.04cvss epss 0.07

    Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages incorrect privilege dropping associated with a locking error.

  • CVE-2015-3798Aug 17, 2015
    risk 0.04cvss epss 0.13

    The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than…

  • CVE-2015-3796Aug 17, 2015
    risk 0.04cvss epss 0.12

    The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than…

  • CVE-2015-3704Jul 3, 2015
    risk 0.04cvss epss 0.09

    runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

  • CVE-2015-3693Jul 3, 2015
    risk 0.04cvss epss 0.08

    Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause a denial of service…

  • CVE-2014-8835Jan 30, 2015
    risk 0.04cvss epss 0.08

    The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type, which allows attackers to execute arbitrary code by providing a crafted dictionary to sysmond, related to an "XPC type confusion"…

  • CVE-2014-8826Jan 30, 2015
    risk 0.04cvss epss 0.09

    LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection mechanism via a crafted JAR archive.

Page 9 of 28