Latest CVE Feed
-
6.8
MEDIUMCVE-2015-5756
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and... Read more
- EPSS Score: %2.10
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5755
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.... Read more
- EPSS Score: %2.81
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-5754
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages incorrect privilege dropping associate... Read more
- EPSS Score: %21.39
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5753
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-378... Read more
- EPSS Score: %2.02
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5752
Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.... Read more
Affected Products : iphone_os- EPSS Score: %0.43
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5751
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-378... Read more
- EPSS Score: %2.51
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-5750
Data Detectors Engine in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted series of Unicode characters.... Read more
- EPSS Score: %0.76
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5749
The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.... Read more
Affected Products : iphone_os- EPSS Score: %0.30
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5748
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.... Read more
- EPSS Score: %0.08
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-5747
The fasttrap driver in the kernel in Apple OS X before 10.10.5 allows local users to cause a denial of service (resource consumption) via unspecified vectors.... Read more
- EPSS Score: %0.04
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5746
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.... Read more
Affected Products : iphone_os- EPSS Score: %0.23
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3807
libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.... Read more
- EPSS Score: %2.36
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3806
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.... Read more
- EPSS Score: %0.05
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3805
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.... Read more
- EPSS Score: %0.06
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3804
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5756 and... Read more
- EPSS Score: %1.99
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3803
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted multi-architecture executable file.... Read more
- EPSS Score: %0.06
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3802
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3805.... Read more
- EPSS Score: %0.06
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3800
The DiskImages component in Apple iOS before 8.4.1 and OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via a malformed DMG image.... Read more
- EPSS Score: %0.07
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3799
The Apple ID OD plug-in in Apple OS X before 10.10.5 allows attackers to change arbitrary user passwords via a crafted app.... Read more
- EPSS Score: %0.50
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3798
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vul... Read more
- EPSS Score: %22.39
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025