Apple

macOS X

3207 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.98%
  • Veröffentlicht 30.01.2015 11:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the XML parser in Foundation in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML docum...

  • EPSS 3.23%
  • Veröffentlicht 30.01.2015 11:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .dfont file.

  • EPSS 2.07%
  • Veröffentlicht 30.01.2015 11:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font file in a PDF document...

  • EPSS 8.61%
  • Veröffentlicht 30.01.2015 11:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

Exploit
  • EPSS 85.45%
  • Veröffentlicht 28.01.2015 19:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 fu...

Exploit
  • EPSS 2.01%
  • Veröffentlicht 18.01.2015 18:59:03
  • Zuletzt bearbeitet 09.06.2025 16:15:24

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-94...

  • EPSS 0.42%
  • Veröffentlicht 15.01.2015 15:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the ses...

  • EPSS 2.53%
  • Veröffentlicht 10.01.2015 19:59:00
  • Zuletzt bearbeitet 09.06.2025 16:15:24

Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image.

  • EPSS 12.97%
  • Veröffentlicht 31.12.2014 02:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact ...

  • EPSS 19.79%
  • Veröffentlicht 15.12.2014 18:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.