|
2921
|
-
5.0
|
MEDIUM
|
The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-download request data.
|
CWE-200
Information Exposure
|
CVE-2015-1110
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2922
|
-
2.1
|
LOW
|
NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.
|
CWE-200
Information Exposure
|
CVE-2015-1109
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2923
|
-
2.1
|
LOW
|
The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain…
|
CWE-200
Information Exposure
|
CVE-2015-1108
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2924
|
-
1.9
|
LOW
|
The Lock Screen component in Apple iOS before 8.3 does not properly implement the erasure feature for incorrect passcode-authentication attempts, which makes it easier for physically proximate attack…
|
NVD-CWE-noinfo
|
CVE-2015-1107
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2925
|
-
2.1
|
LOW
|
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.
|
CWE-200
Information Exposure
|
CVE-2015-1106
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2926
|
-
5.0
|
MEDIUM
|
The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly implement the Urgent (aka out-of-band data) mechanism, which allows …
|
CWE-20
Improper Input Validation
|
CVE-2015-1105
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2927
|
-
5.0
|
MEDIUM
|
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local origin, which allows remote attackers to bypass a…
|
CWE-20
Improper Input Validation
|
CVE-2015-1104
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2928
|
-
7.5
|
HIGH
|
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing changes in response to ICMP_REDIRECT messages, which allows remote attackers to cause a denial of …
|
CWE-20
Improper Input Validation
|
CVE-2015-1103
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2929
|
-
7.1
|
HIGH
|
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly handle TCP headers, which allows man-in-the-middle attackers to cause a denial of service via …
|
CWE-20
Improper Input Validation
|
CVE-2015-1102
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2930
|
-
6.9
|
MEDIUM
|
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrupti…
|
NVD-CWE-noinfo
|
CVE-2015-1101
|
cpe:2.3:o:apple:iphone_os:*:*
|
|
8.2
|
|
|
2024-11-21 11:24
2015-04-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|