|
2821
|
-
5.0
|
MEDIUM
|
Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.
|
CWE-59
Link Following
|
CVE-2015-5752
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:33
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2822
|
-
4.3
|
MEDIUM
|
The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.
|
CWE-200
Information Exposure
|
CVE-2015-5749
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:33
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2823
|
-
2.1
|
LOW
|
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.
|
CWE-17
Code
|
CVE-2015-5748
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:33
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2824
|
-
5.0
|
MEDIUM
|
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.
|
CWE-284
Improper Access Control
|
CVE-2015-5746
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:33
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2825
|
-
4.3
|
MEDIUM
|
libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XM…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3807
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4 9.1
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2826
|
-
7.2
|
HIGH
|
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.
|
CWE-284
Improper Access Control
|
CVE-2015-3806
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2827
|
-
7.2
|
HIGH
|
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.
|
CWE-20
Improper Input Validation
|
CVE-2015-3805
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2828
|
-
7.5
|
HIGH
|
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted fon…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3804
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2829
|
-
7.2
|
HIGH
|
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted multi-architecture executable file.
|
CWE-20
Improper Input Validation
|
CVE-2015-3803
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2830
|
-
7.2
|
HIGH
|
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3805.
|
CWE-20
Improper Input Validation
|
CVE-2015-3802
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|