|
2901
|
-
4.3
|
MEDIUM
|
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1155
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:24
2015-05-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2902
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…
|
NVD-CWE-noinfo
|
CVE-2015-1153
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:24
2015-05-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2903
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…
|
NVD-CWE-noinfo
|
CVE-2015-1152
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.3
|
|
|
2024-11-21 11:24
2015-05-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2904
|
-
4.3
|
MEDIUM
|
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.
|
CWE-310
Cryptographic Issues
|
CVE-2015-1129
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.4.1
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2905
|
-
4.3
|
MEDIUM
|
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers t…
|
CWE-20
Improper Input Validation
|
CVE-2015-1126
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2906
|
-
4.3
|
MEDIUM
|
The touch-events implementation in WebKit in Apple iOS before 8.3 allows remote attackers to trigger an association between a tap and an unintended web resource via a crafted web site.
|
CWE-17
Code
|
CVE-2015-1125
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2907
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denia…
|
NVD-CWE-noinfo
|
CVE-2015-1124
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2908
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted…
|
NVD-CWE-noinfo
|
CVE-2015-1123
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2909
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denia…
|
NVD-CWE-noinfo
|
CVE-2015-1122
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2910
|
-
6.8
|
MEDIUM
|
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denia…
|
NVD-CWE-noinfo
|
CVE-2015-1121
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|