VYPR

Vendor CVEs

Apple Inc.

All CVEs

8,449 total · sorted by risk
  • CVE-2015-6997Oct 23, 2015
    risk 0.00cvss epss 0.01

    The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a…

  • CVE-2015-6992Oct 23, 2015
    risk 0.00cvss epss 0.04

    CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-7017.

  • CVE-2015-6986Oct 23, 2015
    risk 0.00cvss epss 0.03

    com.apple.driver.AppleVXD393 in the Graphics Driver subsystem in Apple iOS before 9.1 allows attackers to execute arbitrary code via a crafted app that leverages an unspecified "type confusion."

  • CVE-2015-6982Oct 23, 2015
    risk 0.00cvss epss 0.02

    WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1.

  • CVE-2015-6981Oct 23, 2015
    risk 0.00cvss epss 0.02

    WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1.

  • CVE-2015-6979Oct 23, 2015
    risk 0.00cvss epss 0.03

    GasGauge in Apple iOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

  • CVE-2015-6975Oct 23, 2015
    risk 0.00cvss epss 0.04

    CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.

  • CVE-2015-7034Oct 18, 2015
    risk 0.00cvss epss 0.03

    The Apple iWork application before 2.6 for iOS and Apple Pages before 5.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Pages document.

  • CVE-2015-7033Oct 18, 2015
    risk 0.00cvss epss 0.03

    The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

  • CVE-2015-7032Oct 18, 2015
    risk 0.00cvss epss 0.02

    The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document.

  • CVE-2015-7761Oct 9, 2015
    risk 0.00cvss epss 0.01

    Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecified action during the printing of an e-mail message, a different vulnerability than CVE-2015-7760.

  • CVE-2015-7760Oct 9, 2015
    risk 0.00cvss epss 0.02

    libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by repeatedly connecting to the SSH port, a different vulnerability than…

  • CVE-2015-5923Oct 9, 2015
    risk 0.00cvss epss 0.00

    Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.

  • CVE-2015-5922Oct 9, 2015
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors.

  • CVE-2015-5919Oct 9, 2015
    risk 0.00cvss epss 0.00

    GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5918.

  • CVE-2015-5918Oct 9, 2015
    risk 0.00cvss epss 0.00

    GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5919.

  • CVE-2015-5917Oct 9, 2015
    risk 0.00cvss epss 0.03

    The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the…

  • CVE-2015-5915Oct 9, 2015
    risk 0.00cvss epss 0.01

    Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified impact and attack vectors.

  • CVE-2015-5914Oct 9, 2015
    risk 0.00cvss epss 0.00

    The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists…

  • CVE-2015-5913Oct 9, 2015
    risk 0.00cvss epss 0.02

    Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request.

  • CVE-2015-5902Oct 9, 2015
    risk 0.00cvss epss 0.00

    The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.

  • CVE-2015-5901Oct 9, 2015
    risk 0.00cvss epss 0.00

    The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.

  • CVE-2015-5900Oct 9, 2015
    risk 0.00cvss epss 0.02

    The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended address.

  • CVE-2015-5897Oct 9, 2015
    risk 0.00cvss epss 0.00

    The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using an environment variable to inject code into processes that rely on this framework.

  • CVE-2015-5894Oct 9, 2015
    risk 0.00cvss epss 0.01

    The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access…

  • CVE-2015-5893Oct 9, 2015
    risk 0.00cvss epss 0.00

    SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

  • CVE-2015-5891Oct 9, 2015
    risk 0.00cvss epss 0.00

    The SMB implementation in the kernel in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

  • CVE-2015-5890Oct 9, 2015
    risk 0.00cvss epss 0.00

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5873.

  • CVE-2015-5888Oct 9, 2015
    risk 0.00cvss epss 0.00

    The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged executable file.

  • CVE-2015-5887Oct 9, 2015
    risk 0.00cvss epss 0.02

    The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a session in which no Server Key Exchange message has been sent, which allows remote attackers to have an unspecified impact via crafted TLS data.

  • CVE-2015-5884Oct 9, 2015
    risk 0.00cvss epss 0.00

    The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.

  • CVE-2015-5883Oct 9, 2015
    risk 0.00cvss epss 0.02

    The bidirectional text-display and text-selection implementations in Terminal in Apple OS X before 10.11 interpret directional override formatting characters differently, which allows remote attackers to spoof the content of a text document via a crafted character sequence.

  • CVE-2015-5878Oct 9, 2015
    risk 0.00cvss epss 0.00

    Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2015-5877Oct 9, 2015
    risk 0.00cvss epss 0.00

    The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5830.

  • CVE-2015-5875Oct 9, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Notes in Apple OS X before 10.11 allows local users to inject arbitrary web script or HTML via crafted text.

  • CVE-2015-5873Oct 9, 2015
    risk 0.00cvss epss 0.00

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5890.

  • CVE-2015-5872Oct 9, 2015
    risk 0.00cvss epss 0.00

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5873, and CVE-2015-5890.

  • CVE-2015-5871Oct 9, 2015
    risk 0.00cvss epss 0.00

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5872, CVE-2015-5873, and CVE-2015-5890.

  • CVE-2015-5870Oct 9, 2015
    risk 0.00cvss epss 0.00

    The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.

  • CVE-2015-5866Oct 9, 2015
    risk 0.00cvss epss 0.03

    IOHIDFamily in Apple OS X before 10.11 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

  • CVE-2015-5865Oct 9, 2015
    risk 0.00cvss epss 0.01

    IOGraphics in Apple OS X before 10.11 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

  • CVE-2015-5864Oct 9, 2015
    risk 0.00cvss epss 0.00

    IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

  • CVE-2015-5854Oct 9, 2015
    risk 0.00cvss epss 0.00

    The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors.

  • CVE-2015-5853Oct 9, 2015
    risk 0.00cvss epss 0.01

    AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors.

  • CVE-2015-5849Oct 9, 2015
    risk 0.00cvss epss 0.02

    The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers to bypass intended access restrictions by leveraging a screen-sharing connection.

  • CVE-2015-5836Oct 9, 2015
    risk 0.00cvss epss 0.01

    Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.

  • CVE-2015-5833Oct 9, 2015
    risk 0.00cvss epss 0.00

    The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access by visiting an unattended workstation.

  • CVE-2015-5830Oct 9, 2015
    risk 0.00cvss epss 0.00

    The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5877.

  • CVE-2015-5828Oct 9, 2015
    risk 0.00cvss epss 0.02

    The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

  • CVE-2015-5780Oct 9, 2015
    risk 0.00cvss epss 0.02

    The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.

Page 117 of 169