|
2871
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corru…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3730
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
|
|
8.4.1
|
2024-11-21 11:29
2015-08-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2872
|
-
5.0
|
MEDIUM
|
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
|
CWE-399
Resource Management Errors
|
CVE-2015-1819
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
9.2.1
|
|
|
2024-11-21 11:26
2015-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2873
|
-
4.3
|
MEDIUM
|
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5523
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:33
2015-08-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2874
|
-
6.8
|
MEDIUM
|
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an hre…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5522
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:33
2015-08-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2875
|
-
4.8
|
MEDIUM
|
The WiFi Connectivity feature in Apple iOS before 8.4 allows remote Wi-Fi access points to trigger an automatic association, with an arbitrary security type, by operating with a recognized ESSID with…
|
CWE-254
7PK - Security Features
|
CVE-2015-3728
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:29
2015-07-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2876
|
-
6.8
|
MEDIUM
|
WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3727
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:29
2015-07-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2877
|
-
4.6
|
MEDIUM
|
The Telephony subsystem in Apple iOS before 8.4 allows physically proximate attackers to execute arbitrary code via a crafted (1) SIM or (2) UIM card.
|
CWE-20
Improper Input Validation
|
CVE-2015-3726
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:29
2015-07-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2878
|
-
4.3
|
MEDIUM
|
MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted…
|
CWE-399
Resource Management Errors
|
CVE-2015-3725
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:29
2015-07-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2879
|
-
6.8
|
MEDIUM
|
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulner…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3724
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:29
2015-07-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2880
|
-
6.8
|
MEDIUM
|
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulner…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3723
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:29
2015-07-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|