|
212831
|
- |
|
apple
|
itunes
|
The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2015-5920
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212832
|
- |
|
apple
|
watchos iphone_os
|
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.
|
CWE-200
Information Exposure
|
CVE-2015-5916
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212833
|
- |
|
apple
|
mac_os_x iphone_os
|
The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
|
CWE-17
Code
|
CVE-2015-5912
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212834
|
- |
|
apple
|
mac_os_x_server
|
Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.
|
NVD-CWE-noinfo
|
CVE-2015-5911
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212835
|
- |
|
apple
|
xcode
|
IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network.
|
CWE-200
Information Exposure
|
CVE-2015-5910
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212836
|
- |
|
apple
|
xcode
|
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunist…
|
CWE-200
Information Exposure
|
CVE-2015-5909
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212837
|
- |
|
apple
|
iphone_os
|
WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.
|
CWE-310
Cryptographic Issues
|
CVE-2015-5907
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212838
|
- |
|
apple
|
iphone_os
|
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a pass…
|
CWE-200
Information Exposure
|
CVE-2015-5906
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212839
|
- |
|
apple
|
iphone_os
|
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.
|
CWE-254
7PK - Security Features
|
CVE-2015-5905
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212840
|
- |
|
apple
|
iphone_os
|
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.
|
CWE-254
7PK - Security Features
|
CVE-2015-5904
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|