|
2841
|
-
9.3
|
HIGH
|
Integer overflow in the kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that makes unspecified IOKit API …
|
CWE-189
Numeric Errors
|
CVE-2015-3768
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2842
|
-
4.3
|
MEDIUM
|
The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the mach_port_space_info interface, which allows attackers to obtain sensitive memory-layout information via a …
|
CWE-200
Information Exposure
|
CVE-2015-3766
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2843
|
-
4.3
|
MEDIUM
|
Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site.
|
CWE-19
Data Processing Errors
|
CVE-2015-3763
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2844
|
-
4.6
|
MEDIUM
|
Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink.
|
CWE-264 CWE-59
Permissions, Privileges, and Access Controls Link Following
|
CVE-2015-3759
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2845
|
-
4.3
|
MEDIUM
|
UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation requirement and initiate arbitrary FaceTime calls via an app that provides a crafted URL.
|
CWE-20
Improper Input Validation
|
CVE-2015-3758
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2846
|
-
2.1
|
LOW
|
The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust…
|
CWE-254
7PK - Security Features
|
CVE-2015-3756
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4
|
|
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2847
|
-
4.3
|
MEDIUM
|
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.
|
CWE-254
7PK - Security Features
|
CVE-2015-3755
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
8.4.1
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2848
|
-
5.0
|
MEDIUM
|
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows…
|
CWE-200
Information Exposure
|
CVE-2015-3753
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
8.4.1
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2849
|
-
5.0
|
MEDIUM
|
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict c…
|
CWE-200
Information Exposure
|
CVE-2015-3752
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
8.4.1
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2850
|
-
5.0
|
MEDIUM
|
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mec…
|
CWE-254
7PK - Security Features
|
CVE-2015-3751
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
8.4.1
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|