Latest CVE Feed
-
5.0
MEDIUMCVE-2015-5906
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that ch... Read more
Affected Products : iphone_os- EPSS Score: %0.39
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5905
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.... Read more
Affected Products : iphone_os- EPSS Score: %0.38
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5904
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.... Read more
Affected Products : iphone_os- EPSS Score: %0.37
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5903
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.... Read more
- EPSS Score: %2.02
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5899
libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more
- EPSS Score: %0.09
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5898
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.... Read more
- EPSS Score: %0.04
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5896
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.... Read more
- EPSS Score: %0.09
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5895
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.... Read more
- EPSS Score: %25.98
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5892
Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5885
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.... Read more
- EPSS Score: %0.78
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5882
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.... Read more
- EPSS Score: %0.07
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5880
CoreAnimation in Apple iOS before 9 allows attackers to bypass intended IOSurface restrictions and obtain screen-framebuffer access via a crafted background app.... Read more
Affected Products : iphone_os- EPSS Score: %0.30
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5879
XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-number protection mechanism and cause a denial of service (TCP connection disruption) via a crafted header.... Read more
- EPSS Score: %1.85
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-5876
dyld in Dev Tools in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more
- EPSS Score: %1.64
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-5874
CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.... Read more
- EPSS Score: %3.21
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2015-5869
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.... Read more
- EPSS Score: %0.45
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5868
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.... Read more
- EPSS Score: %0.07
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-5867
IOHIDFamily in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more
- EPSS Score: %1.08
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5863
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.... Read more
- EPSS Score: %0.06
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5862
The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.... Read more
- EPSS Score: %1.80
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025