|
2681
|
-
7.5
|
HIGH
|
The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via …
|
CWE-20
Improper Input Validation
|
CVE-2015-7036
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:36
2015-11-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2682
|
-
4.3
|
MEDIUM
|
The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS preload list during a Safari private-browsing session, which makes it easier for …
|
CWE-200
Information Exposure
|
CVE-2015-5859
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-11-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2683
|
-
4.3
|
MEDIUM
|
The kernel in Apple iOS before 8.4.1 does not properly restrict debugging features, which allows attackers to bypass background-execution limitations via a crafted app.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5787
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:33
2015-11-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2684
|
-
2.6
|
LOW
|
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML da…
|
CWE-399
Resource Management Errors
|
CVE-2015-8035
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:37
2015-11-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2685
|
-
6.8
|
MEDIUM
|
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a d…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7942
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:37
2015-11-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2686
|
-
5.0
|
MEDIUM
|
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to…
|
NVD-CWE-Other
|
CVE-2015-7995
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2
|
|
|
2024-11-21 11:37
2015-11-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2687
|
-
5.8
|
MEDIUM
|
CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite coo…
|
CWE-17
Code
|
CVE-2015-7023
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2688
|
-
6.8
|
MEDIUM
|
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vuln…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7018
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2689
|
-
6.8
|
MEDIUM
|
Heap-based buffer overflow in the DNS client library in configd in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code via a crafted app tha…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7015
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2690
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicati…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7014
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|