CVE-2015-5921
- EPSS 0.3%
- Veröffentlicht 18.09.2015 12:01:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
CVE-2015-5916
- EPSS 0.56%
- Veröffentlicht 18.09.2015 12:00:57
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.
- EPSS 0.52%
- Veröffentlicht 18.09.2015 12:00:56
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
CVE-2015-5907
- EPSS 0.16%
- Veröffentlicht 18.09.2015 12:00:48
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.
- EPSS 0.39%
- Veröffentlicht 18.09.2015 12:00:46
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing th...
- EPSS 0.38%
- Veröffentlicht 18.09.2015 12:00:44
- Zuletzt bearbeitet 12.04.2025 10:46:40
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.
CVE-2015-5904
- EPSS 0.37%
- Veröffentlicht 18.09.2015 12:00:42
- Zuletzt bearbeitet 12.04.2025 10:46:40
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.
- EPSS 2.02%
- Veröffentlicht 18.09.2015 12:00:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.
CVE-2015-5899
- EPSS 0.09%
- Veröffentlicht 18.09.2015 12:00:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-5898
- EPSS 0.04%
- Veröffentlicht 18.09.2015 12:00:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.