|
2731
|
-
7.5
|
HIGH
|
CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5874
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2732
|
-
3.3
|
LOW
|
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertis…
|
CWE-20
Improper Input Validation
|
CVE-2015-5869
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2733
|
-
7.2
|
HIGH
|
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5868
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2734
|
-
9.3
|
HIGH
|
IOHIDFamily in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5867
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2735
|
-
2.1
|
LOW
|
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
|
CWE-200
Information Exposure
|
CVE-2015-5863
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2736
|
-
4.3
|
MEDIUM
|
The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5862
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2737
|
-
2.1
|
LOW
|
SpringBoard in Apple iOS before 9 allows physically proximate attackers to bypass a lock-screen preview-disabled setting, and reply to an audio message, via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2015-5861
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2738
|
-
5.0
|
MEDIUM
|
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafte…
|
CWE-200
Information Exposure
|
CVE-2015-5860
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2739
|
-
5.0
|
MEDIUM
|
The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.
|
CWE-200
Information Exposure
|
CVE-2015-5858
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2740
|
-
5.0
|
MEDIUM
|
Mail in Apple iOS before 9 allows remote attackers to use an address-book contact as a spoofed e-mail sender address via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2015-5857
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:34
2015-09-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|