|
2701
|
-
7.5
|
HIGH
|
CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7017
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2702
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7005
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2703
|
-
7.1
|
HIGH
|
The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.
|
CWE-20
Improper Input Validation
|
CVE-2015-7004
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2704
|
-
2.1
|
LOW
|
Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phon…
|
CWE-200
Information Exposure
|
CVE-2015-7000
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2705
|
-
5.0
|
MEDIUM
|
The OCSP client in Apple iOS before 9.1 does not check for certificate expiry, which allows remote attackers to spoof a valid certificate by leveraging access to a revoked certificate.
|
CWE-254
7PK - Security Features
|
CVE-2015-6999
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2706
|
-
4.3
|
MEDIUM
|
The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it eas…
|
CWE-254
7PK - Security Features
|
CVE-2015-6997
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2707
|
-
7.5
|
HIGH
|
CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6992
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:36
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2708
|
-
9.3
|
HIGH
|
com.apple.driver.AppleVXD393 in the Graphics Driver subsystem in Apple iOS before 9.1 allows attackers to execute arbitrary code via a crafted app that leverages an unspecified "type confusion."
|
NVD-CWE-Other
|
CVE-2015-6986
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:35
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2709
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6982
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:35
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2710
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6981
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:35
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|