Latest CVE Feed
-
5.8
MEDIUMCVE-2015-5770
MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to replace arbitrary extensions via a crafted enterprise app.... Read more
Affected Products : iphone_os- EPSS Score: %0.36
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-5769
The MSVDX driver in Apple iOS before 8.4.1 allows remote attackers to cause a denial of service (device crash) via a crafted video.... Read more
Affected Products : iphone_os- EPSS Score: %0.83
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5768
AppleGraphicsControl in Apple OS X before 10.10.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.... Read more
- EPSS Score: %0.30
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5766
Directory traversal vulnerability in Air Traffic in Apple iOS before 8.4.1 allows attackers to access arbitrary filesystem locations via vectors related to asset handling.... Read more
Affected Products : iphone_os- EPSS Score: %0.23
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5763
ntfs in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more
- EPSS Score: %0.06
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5761
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5755.... Read more
- EPSS Score: %2.50
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5759
WebKit in Apple iOS before 8.4.1 allows remote attackers to spoof clicks via a crafted web site that leverages tap events.... Read more
Affected Products : iphone_os- EPSS Score: %0.37
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5758
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.... Read more
- EPSS Score: %2.83
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-5757
libpthread in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via an app that uses a crafted syscall to interfere with locking.... Read more
- EPSS Score: %1.08
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5756
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and... Read more
- EPSS Score: %2.10
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5755
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.... Read more
- EPSS Score: %2.81
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-5754
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages incorrect privilege dropping associate... Read more
- EPSS Score: %21.39
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5753
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-378... Read more
- EPSS Score: %2.02
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5752
Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.... Read more
Affected Products : iphone_os- EPSS Score: %0.43
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5751
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-378... Read more
- EPSS Score: %2.51
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-5750
Data Detectors Engine in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted series of Unicode characters.... Read more
- EPSS Score: %0.76
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5749
The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.... Read more
Affected Products : iphone_os- EPSS Score: %0.30
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5748
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.... Read more
- EPSS Score: %0.08
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-5747
The fasttrap driver in the kernel in Apple OS X before 10.10.5 allows local users to cause a denial of service (resource consumption) via unspecified vectors.... Read more
- EPSS Score: %0.04
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5746
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.... Read more
Affected Products : iphone_os- EPSS Score: %0.23
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025