Latest CVE Feed
-
5.0
MEDIUMCVE-2015-7761
Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecified action during the printing of an e-mail message, a different vulnerability than CVE-2015-7760.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7760
libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by repeatedly connecting to the SSH port, a different vulne... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5923
Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5922
Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5919
GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5918.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5918
GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5919.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5917
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by mul... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5915
Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified impact and attack vectors.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
4.7
MEDIUMCVE-2015-5914
The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: ... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5913
Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-5902
The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5901
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-5900
The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended address.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2015-5897
The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using an environment variable to inject code into processes that rely on this framework.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5894
The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoint... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5893
SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5891
The SMB implementation in the kernel in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5890
IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5873.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5889
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5888
The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged executable file.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025