CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2015-8744

    Last Modified: 12 Apr 2025

    QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.

    Published: 12 Oct 2015
    5.5
    Medium

    CVE-2015-8745

    Last Modified: 12 Apr 2025

    QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.

    Published: 12 Oct 2015
    6.2
    Medium

    CVE-2015-8785

    Last Modified: 12 Apr 2025

    The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.

    Published: 12 Oct 2015
    7.8
    High

    CVE-2017-9725

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.

    Published: 12 Oct 2015
    6.5
    Medium

    CVE-2015-5659

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Oct 2015
    6.5
    Medium

    CVE-2015-5648

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Oct 2015
    4
    Medium

    CVE-2015-4929

    Last Modified: 12 Apr 2025

    IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via a REST API request.

    Published: 11 Oct 2015
    5.8
    Medium

    CVE-2015-8242

    Last Modified: 12 Apr 2025

    The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

    Published: 11 Oct 2015
    6.8
    Medium

    CVE-2015-1337

    Last Modified: 12 Apr 2025

    Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

    Published: 9 Oct 2015
    7.5
    High

    CVE-2015-7767

    Last Modified: 12 Apr 2025

    Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long USER command.

    Published: 9 Oct 2015
    7.5
    High

    CVE-2015-7768

    Last Modified: 12 Apr 2025

    Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command.

    Published: 9 Oct 2015
    9
    Critical

    CVE-2015-7766

    Last Modified: 12 Apr 2025

    PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."

    Published: 9 Oct 2015
    9
    Critical

    CVE-2015-7765

    Last Modified: 12 Apr 2025

    ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5833

    Last Modified: 12 Apr 2025

    The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access by visiting an unattended workstation.

    Published: 9 Oct 2015
    6.8
    Medium

    CVE-2015-5849

    Last Modified: 12 Apr 2025

    The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers to bypass intended access restrictions by leveraging a screen-sharing connection.

    Published: 9 Oct 2015
    3.3
    Low

    CVE-2015-5884

    Last Modified: 12 Apr 2025

    The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5901

    Last Modified: 12 Apr 2025

    The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.

    Published: 9 Oct 2015
    4.7
    Medium

    CVE-2015-5914

    Last Modified: 12 Apr 2025

    The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5918

    Last Modified: 12 Apr 2025

    GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5919.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5919

    Last Modified: 12 Apr 2025

    GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5918.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5891

    Last Modified: 12 Apr 2025

    The SMB implementation in the kernel in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 9 Oct 2015
    6.8
    Medium

    CVE-2015-5913

    Last Modified: 12 Apr 2025

    Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request.

    Published: 9 Oct 2015
    1.9
    Low

    CVE-2015-3785

    Last Modified: 12 Apr 2025

    The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

    Published: 9 Oct 2015
    10
    Critical

    CVE-2015-5780

    Last Modified: 12 Apr 2025

    The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.

    Published: 9 Oct 2015
    4.9
    Medium

    CVE-2015-5902

    Last Modified: 12 Apr 2025

    The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.

    Published: 9 Oct 2015
    4.3
    Medium

    CVE-2015-5836

    Last Modified: 12 Apr 2025

    Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.

    Published: 9 Oct 2015
    4.3
    Medium

    CVE-2015-5828

    Last Modified: 12 Apr 2025

    The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5830

    Last Modified: 12 Apr 2025

    The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5877.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5878

    Last Modified: 12 Apr 2025

    Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 9 Oct 2015
    3.3
    Low

    CVE-2015-5853

    Last Modified: 12 Apr 2025

    AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5854

    Last Modified: 12 Apr 2025

    The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5864

    Last Modified: 12 Apr 2025

    IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

    Published: 9 Oct 2015
    4.3
    Medium

    CVE-2015-5865

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.11 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

    Published: 9 Oct 2015
    9.3
    Critical

    CVE-2015-5866

    Last Modified: 12 Apr 2025

    IOHIDFamily in Apple OS X before 10.11 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5870

    Last Modified: 12 Apr 2025

    The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5871

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5872, CVE-2015-5873, and CVE-2015-5890.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5872

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5873, and CVE-2015-5890.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5873

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5890.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5875

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Notes in Apple OS X before 10.11 allows local users to inject arbitrary web script or HTML via crafted text.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5877

    Last Modified: 12 Apr 2025

    The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5830.

    Published: 9 Oct 2015
    Unknown

    CVE-2015-5881

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7760, CVE-2015-7761. Reason: this ID was intended for one issue, but was associated with two issues. Notes: All CVE users should consult CVE-2015-7760 and CVE-2015-7761 to identify the ID or IDs of interest. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Oct 2015
    5
    Medium

    CVE-2015-5883

    Last Modified: 12 Apr 2025

    The bidirectional text-display and text-selection implementations in Terminal in Apple OS X before 10.11 interpret directional override formatting characters differently, which allows remote attackers to spoof the content of a text document via a crafted character sequence.

    Published: 9 Oct 2015
    10
    Critical

    CVE-2015-5887

    Last Modified: 12 Apr 2025

    The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a session in which no Server Key Exchange message has been sent, which allows remote attackers to have an unspecified impact via crafted TLS data.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5888

    Last Modified: 12 Apr 2025

    The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged executable file.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5889

    Last Modified: 12 Apr 2025

    rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables.

    Published: 9 Oct 2015
    7.2
    High

    CVE-2015-5890

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5873.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5893

    Last Modified: 12 Apr 2025

    SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

    Published: 9 Oct 2015
    4.3
    Medium

    CVE-2015-5894

    Last Modified: 12 Apr 2025

    The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.

    Published: 9 Oct 2015
    4.6
    Medium

    CVE-2015-5897

    Last Modified: 12 Apr 2025

    The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using an environment variable to inject code into processes that rely on this framework.

    Published: 9 Oct 2015
    7.1
    High

    CVE-2015-5900

    Last Modified: 12 Apr 2025

    The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended address.

    Published: 9 Oct 2015