CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-3729

    Last Modified: 12 Apr 2025

    Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3731

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3732

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3735

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3736

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3737

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3738

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3739

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3742

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3743

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3744

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3745

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3746

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3749

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

    Published: 16 Aug 2015
    6.4
    Medium

    CVE-2015-3750

    Last Modified: 12 Apr 2025

    WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

    Published: 16 Aug 2015
    5
    Medium

    CVE-2015-3751

    Last Modified: 12 Apr 2025

    WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an IMG element within an OBJECT element.

    Published: 16 Aug 2015
    5
    Medium

    CVE-2015-3753

    Last Modified: 12 Apr 2025

    WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.

    Published: 16 Aug 2015
    2.1
    Low

    CVE-2015-3756

    Last Modified: 12 Apr 2025

    The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.

    Published: 16 Aug 2015
    2.1
    Low

    CVE-2015-3757

    Last Modified: 12 Apr 2025

    Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.

    Published: 16 Aug 2015
    4.3
    Medium

    CVE-2015-3758

    Last Modified: 12 Apr 2025

    UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation requirement and initiate arbitrary FaceTime calls via an app that provides a crafted URL.

    Published: 16 Aug 2015
    4.6
    Medium

    CVE-2015-3759

    Last Modified: 12 Apr 2025

    Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3760

    Last Modified: 12 Apr 2025

    dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unspecified vectors.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3761

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unspecified vectors.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3767

    Last Modified: 12 Apr 2025

    udf in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via a malformed DMG image.

    Published: 16 Aug 2015
    9.3
    Critical

    CVE-2015-3768

    Last Modified: 12 Apr 2025

    Integer overflow in the kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that makes unspecified IOKit API calls.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3769

    Last Modified: 12 Apr 2025

    IOFireWireFamily in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3771 and CVE-2015-3772.

    Published: 16 Aug 2015
    9.3
    Critical

    CVE-2015-3770

    Last Modified: 12 Apr 2025

    IOGraphics in Apple OS X before 10.10.5 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5783.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3771

    Last Modified: 12 Apr 2025

    IOFireWireFamily in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3769 and CVE-2015-3772.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3772

    Last Modified: 12 Apr 2025

    IOFireWireFamily in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3769 and CVE-2015-3771.

    Published: 16 Aug 2015
    7.5
    High

    CVE-2015-3773

    Last Modified: 12 Apr 2025

    The SMB client in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3777

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in blued in the Bluetooth subsystem in Apple OS X before 10.10.5 allow local users to gain privileges via XPC messages.

    Published: 16 Aug 2015
    3.3
    Low

    CVE-2015-3778

    Last Modified: 12 Apr 2025

    bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentially sensitive information about MAC addresses seen in previous Wi-Fi sessions by sniffing an 802.11 network for DNAv4 broadcast traffic.

    Published: 16 Aug 2015
    4.3
    Medium

    CVE-2015-3780

    Last Modified: 12 Apr 2025

    The Bluetooth subsystem in Apple OS X before 10.10.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

    Published: 16 Aug 2015
    4.3
    Medium

    CVE-2015-3781

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Quick Look in Apple OS X before 10.10.5 allows remote attackers to inject arbitrary web script or HTML via a previously visited web site that is rendered during a Quick Look search.

    Published: 16 Aug 2015
    4.3
    Medium

    CVE-2015-3782

    Last Modified: 12 Apr 2025

    CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud user record associated with a previous user's login session via a crafted app.

    Published: 16 Aug 2015
    4.3
    Medium

    CVE-2015-3786

    Last Modified: 12 Apr 2025

    The Bluetooth subsystem in Apple OS X before 10.10.5 does not properly restrict Notification Center Service access, which allows attackers to read Notification Center notifications of certain paired devices via a crafted app.

    Published: 16 Aug 2015
    3.3
    Low

    CVE-2015-3787

    Last Modified: 12 Apr 2025

    The Bluetooth subsystem in Apple OS X before 10.10.5 allows remote attackers to cause a denial of service via malformed Bluetooth ACL packets.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3788

    Last Modified: 12 Apr 2025

    QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3789

    Last Modified: 12 Apr 2025

    QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3790

    Last Modified: 12 Apr 2025

    QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.

    Published: 16 Aug 2015
    6.8
    Medium

    CVE-2015-3791

    Last Modified: 12 Apr 2025

    QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.

    Published: 16 Aug 2015
    4.3
    Medium

    CVE-2015-3793

    Last Modified: 12 Apr 2025

    CFPreferences in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.

    Published: 16 Aug 2015
    7.5
    High

    CVE-2015-3796

    Last Modified: 12 Apr 2025

    The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3797 and CVE-2015-3798.

    Published: 16 Aug 2015
    7.5
    High

    CVE-2015-3797

    Last Modified: 12 Apr 2025

    The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3796 and CVE-2015-3798.

    Published: 16 Aug 2015
    7.5
    High

    CVE-2015-3798

    Last Modified: 12 Apr 2025

    The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3796 and CVE-2015-3797.

    Published: 16 Aug 2015
    9.3
    Critical

    CVE-2015-3799

    Last Modified: 12 Apr 2025

    The Apple ID OD plug-in in Apple OS X before 10.10.5 allows attackers to change arbitrary user passwords via a crafted app.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3802

    Last Modified: 12 Apr 2025

    Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3805.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3803

    Last Modified: 12 Apr 2025

    Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted multi-architecture executable file.

    Published: 16 Aug 2015
    7.5
    High

    CVE-2015-3804

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5756 and CVE-2015-5775.

    Published: 16 Aug 2015
    7.2
    High

    CVE-2015-3805

    Last Modified: 12 Apr 2025

    Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.

    Published: 16 Aug 2015