Latest CVE Feed
-
5.0
MEDIUMCVE-2015-1147
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-1146
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1145.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-1145
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1146.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1144
Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted Uniform Type Identifier.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1143
LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1142
LaunchServices in Apple OS X before 10.10.3 allows local users to cause a denial of service (Finder crash) via crafted localization data.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-1141
The mach_vm_read functionality in the kernel in Apple OS X before 10.10.3 allows local users to cause a denial of service (system crash) via unspecified vectors.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1140
Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1139
ImageIO in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .sgi file.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-1138
Hypervisor in Apple OS X before 10.10.3 allows local users to cause a denial of service via unspecified vectors.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1137
The NVIDIA graphics driver in Apple OS X before 10.10.3 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via an unspecified IOService userclient type.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1136
Use-after-free vulnerability in CoreAnimation in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code by leveraging improper use of a mutex.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1135
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1134.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1134
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1135.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1133
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1134, and CVE-2015-1135.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1132
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1131
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1132, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-1130
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.... Read more
- Actively Exploited
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1129
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1128
The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history information via vectors involving push-notification requests.... Read more
Affected Products : safari- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025