CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-3690

    Last Modified: 12 Apr 2025

    The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3697

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.

    Published: 3 Jul 2015
    9.3
    Critical

    CVE-2015-3706

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3705.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3715

    Last Modified: 12 Apr 2025

    The code-signing implementation in Apple OS X before 10.10.4 does not properly consider libraries that are external to an application bundle, which allows attackers to bypass intended launch restrictions via a crafted library.

    Published: 3 Jul 2015
    7.5
    High

    CVE-2015-3717

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 3 Jul 2015
    4.3
    Medium

    CVE-2015-3725

    Last Modified: 12 Apr 2025

    MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.

    Published: 3 Jul 2015
    4.3
    Medium

    CVE-2015-3660

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3668

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, and CVE-2015-3667.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3681

    Last Modified: 12 Apr 2025

    Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015-3682.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3689

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, and CVE-2015-3688.

    Published: 3 Jul 2015
    9.3
    Critical

    CVE-2015-3707

    Last Modified: 12 Apr 2025

    The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 3 Jul 2015
    4.4
    Medium

    CVE-2015-3716

    Last Modified: 12 Apr 2025

    Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3718

    Last Modified: 12 Apr 2025

    systemstatsd in the System Stats subsystem in Apple OS X before 10.10.4 does not properly interpret data types encountered in interprocess communication, which allows attackers to execute arbitrary code with systemstatsd privileges via a crafted app, related to a "type confusion" issue.

    Published: 3 Jul 2015
    4.6
    Medium

    CVE-2015-3726

    Last Modified: 12 Apr 2025

    The Telephony subsystem in Apple iOS before 8.4 allows physically proximate attackers to execute arbitrary code via a crafted (1) SIM or (2) UIM card.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3727

    Last Modified: 12 Apr 2025

    WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3679

    Last Modified: 12 Apr 2025

    Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3680, CVE-2015-3681, and CVE-2015-3682.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3658

    Last Modified: 12 Apr 2025

    The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site.

    Published: 3 Jul 2015
    9.3
    Critical

    CVE-2015-3705

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3706.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3661

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3662

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3663

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3664

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3665 and CVE-2015-3669.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3665

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3669.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3666

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3667, and CVE-2015-3668.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3669

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3665.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3673

    Last Modified: 12 Apr 2025

    Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.

    Published: 3 Jul 2015
    7.5
    High

    CVE-2015-3674

    Last Modified: 12 Apr 2025

    afpserver in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 3 Jul 2015
    5
    Medium

    CVE-2015-3675

    Last Modified: 12 Apr 2025

    The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attackers to bypass HTTP authentication via a crafted URL.

    Published: 3 Jul 2015
    4.3
    Medium

    CVE-2015-3676

    Last Modified: 12 Apr 2025

    AppleGraphicsControl in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information via a crafted app.

    Published: 3 Jul 2015
    4.3
    Medium

    CVE-2015-3677

    Last Modified: 12 Apr 2025

    The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3678

    Last Modified: 12 Apr 2025

    AppleThunderboltEDMService in Apple OS X before 10.10.4 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified Thunderbolt commands.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3682

    Last Modified: 12 Apr 2025

    Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015-3681.

    Published: 3 Jul 2015
    9.3
    Critical

    CVE-2015-3683

    Last Modified: 12 Apr 2025

    The Bluetooth HCI interface implementation in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3684

    Last Modified: 12 Apr 2025

    The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted credentials in a URL.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3685

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3686, CVE-2015-3687, CVE-2015-3688, and CVE-2015-3689.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3686

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3687, CVE-2015-3688, and CVE-2015-3689.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3687

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3688, and CVE-2015-3689.

    Published: 3 Jul 2015
    9.3
    Critical

    CVE-2015-3691

    Last Modified: 12 Apr 2025

    The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages control of a function pointer.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3692

    Last Modified: 12 Apr 2025

    Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging root privileges.

    Published: 3 Jul 2015
    9.3
    Critical

    CVE-2015-3693

    Last Modified: 12 Apr 2025

    Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause a denial of service (memory corruption), by triggering certain patterns of access to memory locations.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3694

    Last Modified: 12 Apr 2025

    FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3719.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3695

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3696

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3698

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3699

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3700

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3701, and CVE-2015-3702.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3701

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3702.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3702

    Last Modified: 12 Apr 2025

    Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3701.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3703

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image.

    Published: 3 Jul 2015
    9.3
    Critical

    CVE-2015-3704

    Last Modified: 12 Apr 2025

    runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 3 Jul 2015