CVE-2015-5836
- EPSS 0.29%
- Veröffentlicht 09.10.2015 05:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.
CVE-2015-5833
- EPSS 0.07%
- Veröffentlicht 09.10.2015 05:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access by visiting an unattended workstation.
CVE-2015-5830
- EPSS 0.06%
- Veröffentlicht 09.10.2015 05:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5877.
CVE-2015-3785
- EPSS 0.09%
- Veröffentlicht 09.10.2015 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.
- EPSS 0.52%
- Veröffentlicht 18.09.2015 12:00:56
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
- EPSS 2.02%
- Veröffentlicht 18.09.2015 12:00:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.
CVE-2015-5899
- EPSS 0.09%
- Veröffentlicht 18.09.2015 12:00:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-5896
- EPSS 0.09%
- Veröffentlicht 18.09.2015 12:00:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.
- EPSS 0.78%
- Veröffentlicht 18.09.2015 12:00:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
CVE-2015-5882
- EPSS 0.07%
- Veröffentlicht 18.09.2015 12:00:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.