Apple

macOS X

3207 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 75.52%
  • Published 09.06.2015 18:59:06
  • Last modified 12.04.2025 10:46:40

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form ...

Exploit
  • EPSS 20.64%
  • Published 09.06.2015 18:59:05
  • Last modified 12.04.2025 10:46:40

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer ove...

Exploit
  • EPSS 42.03%
  • Published 09.06.2015 18:59:04
  • Last modified 12.04.2025 10:46:40

The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote attackers to cause a de...

Exploit
  • EPSS 38.96%
  • Published 09.06.2015 18:59:03
  • Last modified 12.04.2025 10:46:40

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or p...

Exploit
  • EPSS 28.15%
  • Published 09.06.2015 18:59:02
  • Last modified 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) ph...

Exploit
  • EPSS 18.41%
  • Published 09.06.2015 18:59:01
  • Last modified 12.04.2025 10:46:40

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a craf...

Exploit
  • EPSS 9.68%
  • Published 09.06.2015 18:59:00
  • Last modified 12.04.2025 10:46:40

ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length v...

Exploit
  • EPSS 3.1%
  • Published 28.05.2015 01:59:00
  • Last modified 12.04.2025 10:46:40

CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated...

Exploit
  • EPSS 40.41%
  • Published 25.05.2015 22:59:01
  • Last modified 12.04.2025 10:46:40

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which all...

Exploit
  • EPSS 40.13%
  • Published 25.05.2015 22:59:00
  • Last modified 12.04.2025 10:46:40

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows ...