Latest CVE Feed
-
2.1
LOWCVE-2015-3757
Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.... Read more
- EPSS Score: %0.05
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-3756
The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.... Read more
Affected Products : iphone_os- EPSS Score: %0.04
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3755
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.... Read more
- EPSS Score: %1.39
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3754
The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web sit... Read more
Affected Products : safari- EPSS Score: %0.50
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3753
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and o... Read more
- EPSS Score: %0.62
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3752
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows rem... Read more
- EPSS Score: %1.12
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3751
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an I... Read more
- EPSS Score: %1.55
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-3750
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests,... Read more
- EPSS Score: %0.77
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3749
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3748
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3747
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3746
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3745
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3744
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3743
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3742
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3741
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3740
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.00
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3739
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.64
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3738
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a d... Read more
- EPSS Score: %1.08
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025