CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2015-6996

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7003

    Last Modified: 12 Apr 2025

    coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure, which allows attackers to execute arbitrary code via a crafted app.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7006

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO archive.

    Published: 23 Oct 2015
    7.5
    High

    CVE-2015-7007

    Last Modified: 12 Apr 2025

    Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7010

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7018.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7011

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7012

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7013

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7014

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.

    Published: 23 Oct 2015
    5.6
    Medium

    CVE-2015-7019

    Last Modified: 12 Apr 2025

    The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different vulnerability than CVE-2015-7020.

    Published: 23 Oct 2015
    5.6
    Medium

    CVE-2015-7020

    Last Modified: 12 Apr 2025

    The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different vulnerability than CVE-2015-7019.

    Published: 23 Oct 2015
    7.2
    High

    CVE-2015-7021

    Last Modified: 12 Apr 2025

    The Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to gain privileges or cause a denial of service (kernel memory corruption) via unspecified vectors.

    Published: 23 Oct 2015
    5
    Medium

    CVE-2015-6999

    Last Modified: 12 Apr 2025

    The OCSP client in Apple iOS before 9.1 does not check for certificate expiry, which allows remote attackers to spoof a valid certificate by leveraging access to a revoked certificate.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6982

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1.

    Published: 23 Oct 2015
    2.1
    Low

    CVE-2015-7000

    Last Modified: 12 Apr 2025

    Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon after a setting was disabled.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-6981

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1.

    Published: 23 Oct 2015
    7.5
    High

    CVE-2015-6975

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.

    Published: 23 Oct 2015
    9.3
    Critical

    CVE-2015-6979

    Last Modified: 12 Apr 2025

    GasGauge in Apple iOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 23 Oct 2015
    9.3
    Critical

    CVE-2015-6986

    Last Modified: 12 Apr 2025

    com.apple.driver.AppleVXD393 in the Graphics Driver subsystem in Apple iOS before 9.1 allows attackers to execute arbitrary code via a crafted app that leverages an unspecified "type confusion."

    Published: 23 Oct 2015
    7.5
    High

    CVE-2015-6992

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-7017.

    Published: 23 Oct 2015
    4.3
    Medium

    CVE-2015-6997

    Last Modified: 12 Apr 2025

    The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

    Published: 23 Oct 2015
    7.1
    High

    CVE-2015-7004

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7005

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1.

    Published: 23 Oct 2015
    7.5
    High

    CVE-2015-7017

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992.

    Published: 23 Oct 2015
    4.3
    Medium

    CVE-2015-7022

    Last Modified: 12 Apr 2025

    The Telephony subsystem in Apple iOS before 9.1 allows attackers to obtain sensitive call-status information via a crafted app.

    Published: 23 Oct 2015
    7.5
    High

    CVE-2015-7030

    Last Modified: 12 Apr 2025

    The Swift implementation in Apple Xcode before 7.1 mishandles type conversion, which has unspecified impact and attack vectors.

    Published: 23 Oct 2015
    5
    Medium

    CVE-2015-7031

    Last Modified: 12 Apr 2025

    The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.

    Published: 23 Oct 2015
    7.5
    High

    CVE-2015-7035

    Last Modified: 12 Apr 2025

    Apple Mac EFI before 2015-002, as used in OS X before 10.11.1 and other products, mishandles arguments, which allows attackers to reach "unused" functions via unspecified vectors.

    Published: 23 Oct 2015
    6.8
    Medium

    CVE-2015-7942

    Last Modified: 12 Apr 2025

    The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

    Published: 22 Oct 2015
    5
    Medium

    CVE-2015-7981

    Last Modified: 12 Apr 2025

    The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an out-of-bounds read.

    Published: 22 Oct 2015
    4
    Medium

    CVE-2015-4838

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.4.0, 12.1.2.0.0, and 12.1.3.0.0 allows remote authenticated users to affect confidentiality via vectors related to ADF Faces.

    Published: 21 Oct 2015
    10
    Critical

    CVE-2015-4839

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to DB Listener, a different vulnerability than CVE-2015-4798.

    Published: 21 Oct 2015
    4.3
    Medium

    CVE-2015-4854

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Single Signon. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is a cross-site scripting (XSS) vulnerability, which allows remote attackers to inject arbitrary web script or HTML via the Domain parameter in the CfgOCIReturn servlet.

    Published: 21 Oct 2015
    5.8
    Medium

    CVE-2015-4859

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Agent Next Gen.

    Published: 21 Oct 2015
    4.1
    Medium

    CVE-2015-4874

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4898

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via vectors related to Diagnostics and DMZ.

    Published: 21 Oct 2015
    4.6
    Medium

    CVE-2015-4907

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2015-4820.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4914

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 10.1.3.5, 11.1.1.7, 11.1.1.9, 12.1.2.0, and 12.1.3.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web Listener.

    Published: 21 Oct 2015
    3.7
    Low

    CVE-2015-4834

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Zones.

    Published: 21 Oct 2015
    6.6
    Medium

    CVE-2015-4837

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Security.

    Published: 21 Oct 2015
    4.3
    Medium

    CVE-2015-4841

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM IP2014 and IP2015 allows remote attackers to affect confidentiality via unknown vectors related to Services.

    Published: 21 Oct 2015
    4.3
    Medium

    CVE-2015-4845

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via vectors related to Java APIs - AOL/J. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to enumerate database users via a series of requests to Aoljtest.js.

    Published: 21 Oct 2015
    3.6
    Low

    CVE-2015-4846

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to SQL Extensions. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is a SQL injection vulnerability, which allows remote authenticated users to execute arbitrary SQL commands via a request involving the afamexts.sql SQL extension.

    Published: 21 Oct 2015
    4.3
    Medium

    CVE-2015-4847

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to OCI.

    Published: 21 Oct 2015
    5
    Medium

    CVE-2015-4848

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors related to Integration with Peoplesoft.

    Published: 21 Oct 2015
    6.8
    Medium

    CVE-2015-4849

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Payments component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Punch-in. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to cause a denial of service or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/IspPunchInServlet.

    Published: 21 Oct 2015
    5.5
    Medium

    CVE-2015-4850

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.

    Published: 21 Oct 2015
    6.8
    Medium

    CVE-2015-4851

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to XML input. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/oramipp_lpr.

    Published: 21 Oct 2015
    4.9
    Medium

    CVE-2015-4856

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.30, 4.1.38, 4.2.30, 4.3.26, and 5.0.0 allows local users to affect availability via unknown vectors related to Core.

    Published: 21 Oct 2015
    5.5
    Medium

    CVE-2015-4857

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the RDBMS component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 21 Oct 2015