- EPSS 0.3%
- Published 10.04.2015 14:59:58
- Last modified 12.04.2025 10:46:40
Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sensitive information by reading this file.
- EPSS 0.45%
- Published 10.04.2015 14:59:57
- Last modified 12.04.2025 10:46:40
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.
CVE-2015-1146
- EPSS 0.07%
- Published 10.04.2015 14:59:56
- Last modified 12.04.2025 10:46:40
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1145.
CVE-2015-1145
- EPSS 0.07%
- Published 10.04.2015 14:59:55
- Last modified 12.04.2025 10:46:40
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1146.
CVE-2015-1144
- EPSS 0.05%
- Published 10.04.2015 14:59:54
- Last modified 12.04.2025 10:46:40
Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted Uniform Type Identifier.
CVE-2015-1142
- EPSS 0.06%
- Published 10.04.2015 14:59:53
- Last modified 12.04.2025 10:46:40
LaunchServices in Apple OS X before 10.10.3 allows local users to cause a denial of service (Finder crash) via crafted localization data.
CVE-2015-1143
- EPSS 0.06%
- Published 10.04.2015 14:59:53
- Last modified 12.04.2025 10:46:40
LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue.
CVE-2015-1141
- EPSS 0.05%
- Published 10.04.2015 14:59:52
- Last modified 12.04.2025 10:46:40
The mach_vm_read functionality in the kernel in Apple OS X before 10.10.3 allows local users to cause a denial of service (system crash) via unspecified vectors.
CVE-2015-1140
- EPSS 0.89%
- Published 10.04.2015 14:59:51
- Last modified 12.04.2025 10:46:40
Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors.
CVE-2015-1139
- EPSS 1.97%
- Published 10.04.2015 14:59:50
- Last modified 12.04.2025 10:46:40
ImageIO in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .sgi file.