CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2015-6324

    Last Modified: 12 Apr 2025

    The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) software 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3 before 9.3(3.5), and 9.4 before 9.4(2) allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug IDs CSCus56252 and CSCus57142.

    Published: 25 Oct 2015
    7.8
    High

    CVE-2015-6327

    Last Modified: 12 Apr 2025

    The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.8), 9.2 before 9.2(4), and 9.3 before 9.3(3) allows remote attackers to cause a denial of service (device reload) via crafted ISAKMP UDP packets, aka Bug ID CSCus94026.

    Published: 25 Oct 2015
    5
    Medium

    CVE-2015-6341

    Last Modified: 12 Apr 2025

    The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610.

    Published: 25 Oct 2015
    5
    Medium

    CVE-2015-6484

    Last Modified: 12 Apr 2025

    3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request.

    Published: 25 Oct 2015
    5.5
    Medium

    CVE-2015-9261

    Last Modified: 21 Nov 2024

    huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.

    Published: 25 Oct 2015
    6
    Medium

    CVE-2015-7549

    Last Modified: 20 Apr 2025

    The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by leveraging failure to define the .write method.

    Published: 24 Oct 2015
    7.5
    High

    CVE-2015-8315

    Last Modified: 20 Apr 2025

    The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

    Published: 24 Oct 2015
    6.8
    Medium

    CVE-2015-5925

    Last Modified: 12 Apr 2025

    The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5926.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5933

    Last Modified: 12 Apr 2025

    Audio in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, a different vulnerability than CVE-2015-5934.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5942

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5927.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6990

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7002

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7008

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7015

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the DNS client library in configd in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code via a crafted app that sends a spoofed configd response to a client.

    Published: 23 Oct 2015
    5.8
    Medium

    CVE-2015-7023

    Last Modified: 12 Apr 2025

    CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5926

    Last Modified: 12 Apr 2025

    The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5928

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5930

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5934

    Last Modified: 12 Apr 2025

    Audio in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, a different vulnerability than CVE-2015-5933.

    Published: 23 Oct 2015
    4.3
    Medium

    CVE-2015-5943

    Last Modified: 12 Apr 2025

    SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a crafted app.

    Published: 23 Oct 2015
    8.8
    High

    CVE-2015-6983

    Last Modified: 12 Apr 2025

    Double free vulnerability in Apple iOS before 9.1 and OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that accesses AtomicBufferedFile descriptors.

    Published: 23 Oct 2015
    10
    Critical

    CVE-2015-6988

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data structure, which allows remote attackers to execute arbitrary code via vectors involving an unknown network-connectivity requirement.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6991

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7009

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    7.6
    High

    CVE-2015-7016

    Last Modified: 12 Apr 2025

    The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, which allows attackers to bypass intended entitlement restrictions and gain privileges via a crafted developer-signed app.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7018

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7010.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5944

    Last Modified: 12 Apr 2025

    CoreText in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.

    Published: 23 Oct 2015
    7.2
    High

    CVE-2015-5945

    Last Modified: 12 Apr 2025

    The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5924

    Last Modified: 12 Apr 2025

    The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5927

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5942.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5929

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5931

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    7.2
    High

    CVE-2015-5932

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X before 10.11.1 allows local users to gain privileges by leveraging an unspecified "type confusion" during Mach task processing.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5935

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5936, CVE-2015-5937, and CVE-2015-5939.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5936

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5937, and CVE-2015-5939.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5937

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5939.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5938

    Last Modified: 12 Apr 2025

    ImageIO in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5939

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5937.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-5940

    Last Modified: 12 Apr 2025

    The Accelerate Framework component in Apple iOS before 9.1 and OS X before 10.11.1, when multi-threading is enabled, omits certain validation and locking steps, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 23 Oct 2015
    9.3
    Critical

    CVE-2015-6974

    Last Modified: 12 Apr 2025

    IOHIDFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6976

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6977

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6978

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    8.8
    High

    CVE-2015-6984

    Last Modified: 12 Apr 2025

    libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that conducts an unspecified symlink attack.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6985

    Last Modified: 12 Apr 2025

    Apple Type Services (ATS) in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web page.

    Published: 23 Oct 2015
    2.1
    Low

    CVE-2015-6987

    Last Modified: 12 Apr 2025

    The File Bookmark component in Apple OS X before 10.11.1 allows local users to cause a denial of service (application crash) via crafted bookmark metadata in a folder.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6989

    Last Modified: 12 Apr 2025

    Grand Central Dispatch in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted package that is mishandled during dispatch calls.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6993

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.

    Published: 23 Oct 2015
    7.1
    High

    CVE-2015-6994

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.1 and OS X before 10.11.1 mishandles reuse of virtual memory, which allows attackers to cause a denial of service via a crafted app.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6995

    Last Modified: 12 Apr 2025

    The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

    Published: 23 Oct 2015