CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2015-7059

    Last Modified: 12 Apr 2025

    The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7060 and CVE-2015-7061.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7061

    Last Modified: 12 Apr 2025

    The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7059 and CVE-2015-7060.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7070

    Last Modified: 12 Apr 2025

    Mobile Replayer in GPUTools Framework in Apple iOS before 9.2 allows attackers to execute arbitrary code in a privileged context via an app that provides a crafted pathname, a different vulnerability than CVE-2015-7069.

    Published: 11 Dec 2015
    10
    Critical

    CVE-2015-7082

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Git before 2.5.4, as used in Apple Xcode before 7.2, have unknown impact and attack vectors. NOTE: this CVE is associated only with Xcode use cases.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7083

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7084.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7096

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7103

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, and CVE-2015-7102.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7112

    Last Modified: 12 Apr 2025

    The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7111.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7065

    Last Modified: 12 Apr 2025

    OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7066

    Last Modified: 12 Apr 2025

    OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7064.

    Published: 11 Dec 2015
    5
    Medium

    CVE-2015-7037

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Mobile Backup in Photos in Apple iOS before 9.2 allows attackers to read arbitrary files via a crafted pathname.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7039

    Last Modified: 12 Apr 2025

    Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7038.

    Published: 11 Dec 2015
    4.3
    Medium

    CVE-2015-7042

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7043.

    Published: 11 Dec 2015
    4.3
    Medium

    CVE-2015-7043

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7042.

    Published: 11 Dec 2015
    7.6
    High

    CVE-2015-7044

    Last Modified: 12 Apr 2025

    The System Integrity Protection feature in Apple OS X before 10.11.2 mishandles union mounts, which allows attackers to execute arbitrary code in a privileged context via a crafted app with root privileges.

    Published: 11 Dec 2015
    5
    Medium

    CVE-2015-7045

    Last Modified: 12 Apr 2025

    Keychain Access in Apple OS X before 10.11.2 and tvOS before 9.1 improperly interacts with Keychain Agent, which allows attackers to spoof the Keychain Server via unspecified vectors.

    Published: 11 Dec 2015
    2.6
    Low

    CVE-2015-7046

    Last Modified: 12 Apr 2025

    The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ASLR protection mechanism via a crafted app with root privileges.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7047

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted mach message that is misparsed.

    Published: 11 Dec 2015
    4.3
    Medium

    CVE-2015-7050

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2 and Safari before 9.0.2 misparses content extensions, which allows remote attackers to obtain sensitive browsing-history information via a crafted web site.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7051

    Last Modified: 12 Apr 2025

    MobileStorageMounter in Apple iOS before 9.2 and tvOS before 9.1 mishandles the timing of trust-cache loading, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7052

    Last Modified: 12 Apr 2025

    kext tools in Apple OS X before 10.11.2 mishandles kernel-extension loading, which allows local users to gain privileges via unspecified vectors.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7053

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7054

    Last Modified: 12 Apr 2025

    zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not initialize memory for an unspecified data structure, which allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7055

    Last Modified: 12 Apr 2025

    AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 11 Dec 2015
    4.3
    Medium

    CVE-2015-7058

    Last Modified: 12 Apr 2025

    Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 improperly validate keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7060

    Last Modified: 12 Apr 2025

    The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7059 and CVE-2015-7061.

    Published: 11 Dec 2015
    4.6
    Medium

    CVE-2015-7062

    Last Modified: 12 Apr 2025

    Apple OS X before 10.11.2 and tvOS before 9.1 allow local users to bypass intended configuration-profile installation restrictions via unspecified vectors.

    Published: 11 Dec 2015
    7.8
    High

    CVE-2015-7068

    Last Modified: 12 Apr 2025

    IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.

    Published: 11 Dec 2015
    10
    Critical

    CVE-2015-7071

    Last Modified: 12 Apr 2025

    The File Bookmark component in Apple OS X before 10.11.2 allows attackers to bypass a sandbox protection mechanism for app scoped bookmarks via a crafted pathname.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7072

    Last Modified: 12 Apr 2025

    dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7074

    Last Modified: 12 Apr 2025

    CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7075

    Last Modified: 12 Apr 2025

    CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.

    Published: 11 Dec 2015
    2.1
    Low

    CVE-2015-7080

    Last Modified: 12 Apr 2025

    Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7084

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.

    Published: 11 Dec 2015
    6.9
    Medium

    CVE-2015-7110

    Last Modified: 12 Apr 2025

    The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image.

    Published: 11 Dec 2015
    4.3
    Medium

    CVE-2015-7093

    Last Modified: 12 Apr 2025

    Safari in Apple iOS before 9.2 allows remote attackers to spoof a URL in the user interface via a crafted web site.

    Published: 11 Dec 2015
    2.6
    Low

    CVE-2015-7094

    Last Modified: 12 Apr 2025

    CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7097

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7098

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7099

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7100

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7101

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7104

    Last Modified: 12 Apr 2025

    WebKit in Apple Safari before 9.0.2 and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7106

    Last Modified: 12 Apr 2025

    The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7107

    Last Modified: 12 Apr 2025

    QuickLook in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7108

    Last Modified: 12 Apr 2025

    The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7109

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple OS X before 10.11.2 and tvOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 11 Dec 2015
    10
    Critical

    CVE-2015-7113

    Last Modified: 12 Apr 2025

    The LaunchServices component in Apple iOS before 9.2 and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a malformed plist.

    Published: 11 Dec 2015
    2.5
    Low

    CVE-2015-5313

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.

    Published: 11 Dec 2015
    6.1
    Medium

    CVE-2015-9097

    Last Modified: 20 Apr 2025

    The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.

    Published: 11 Dec 2015