CVE-2016-1717
- EPSS 0.08%
- Veröffentlicht 01.02.2016 11:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
- EPSS 2.19%
- Veröffentlicht 12.01.2016 19:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
CVE-2015-8242
- EPSS 1.17%
- Veröffentlicht 15.12.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive informati...
- EPSS 1.27%
- Veröffentlicht 15.12.2015 21:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
- EPSS 2.21%
- Veröffentlicht 15.12.2015 21:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
CVE-2015-5312
- EPSS 0.71%
- Veröffentlicht 15.12.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerab...
- EPSS 0.87%
- Veröffentlicht 11.12.2015 12:00:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The LaunchServices component in Apple iOS before 9.2 and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a malformed plist.
CVE-2015-7112
- EPSS 19.67%
- Veröffentlicht 11.12.2015 12:00:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a differe...
CVE-2015-7111
- EPSS 1.73%
- Veröffentlicht 11.12.2015 12:00:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a differe...
CVE-2015-7105
- EPSS 2.53%
- Veröffentlicht 11.12.2015 12:00:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
CoreGraphics in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.