Latest CVE Feed
-
7.5
HIGHCVE-2015-3717
Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.... Read more
- EPSS Score: %1.44
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2015-3716
Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.... Read more
- EPSS Score: %0.14
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3715
The code-signing implementation in Apple OS X before 10.10.4 does not properly consider libraries that are external to an application bundle, which allows attackers to bypass intended launch restrictions via a crafted library.... Read more
- EPSS Score: %0.57
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3714
Apple OS X before 10.10.4 does not properly consider custom resource rules during app signature verification, which allows attackers to bypass intended launch restrictions via a modified app.... Read more
- EPSS Score: %0.29
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3713
QuickTime in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted movie file.... Read more
- EPSS Score: %1.40
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3712
The NVIDIA graphics driver in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds write) via a crafted app.... Read more
- EPSS Score: %1.04
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3711
The NTFS implementation in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.... Read more
- EPSS Score: %0.30
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3710
Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh operation, and consequently cause a visit to an arbitrary web site, via a crafted HTML e-mail message.... Read more
- EPSS Score: %0.52
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-3709
Race condition in kext tools in Apple OS X before 10.10.4 allows local users to bypass intended signature requirements for kernel extensions by leveraging improper pathname validation.... Read more
- EPSS Score: %0.04
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2015-3708
kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a crafted app that conducts a symlink attack.... Read more
- EPSS Score: %0.50
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3707
The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.... Read more
- EPSS Score: %2.20
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3706
IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3705.... Read more
- EPSS Score: %1.13
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3705
IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3706.... Read more
- EPSS Score: %1.13
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3704
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.... Read more
- EPSS Score: %37.86
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3703
ImageIO in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image.... Read more
- EPSS Score: %1.90
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3702
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-370... Read more
- EPSS Score: %0.05
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3701
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-370... Read more
- EPSS Score: %0.14
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3700
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-370... Read more
- EPSS Score: %0.05
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3699
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3700, CVE-2015-370... Read more
- EPSS Score: %0.14
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3698
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3699, CVE-2015-3700, CVE-2015-370... Read more
- EPSS Score: %0.14
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025