|
2711
|
-
9.3
|
HIGH
|
GasGauge in Apple iOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6979
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:35
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2712
|
-
7.5
|
HIGH
|
CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6975
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.2
|
|
|
2024-11-21 11:35
2015-10-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2713
|
-
2.1
|
LOW
|
Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-5923
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.0.1
|
|
|
2024-11-21 11:34
2015-10-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2714
|
-
4.3
|
MEDIUM
|
WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-5921
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2715
|
-
4.3
|
MEDIUM
|
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.
|
CWE-200
Information Exposure
|
CVE-2015-5916
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2716
|
-
5.0
|
MEDIUM
|
The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
|
CWE-17
Code
|
CVE-2015-5912
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2717
|
-
2.6
|
LOW
|
WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.
|
CWE-310
Cryptographic Issues
|
CVE-2015-5907
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2718
|
-
5.0
|
MEDIUM
|
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a pass…
|
CWE-200
Information Exposure
|
CVE-2015-5906
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2719
|
-
5.0
|
MEDIUM
|
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.
|
CWE-254
7PK - Security Features
|
CVE-2015-5905
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2720
|
-
4.3
|
MEDIUM
|
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.
|
CWE-254
7PK - Security Features
|
CVE-2015-5904
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|