Apple

macOS X

3207 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.87%
  • Published 18.03.2015 22:59:01
  • Last modified 12.04.2025 10:46:40

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnera...

  • EPSS 1.17%
  • Published 12.03.2015 10:59:11
  • Last modified 12.04.2025 10:46:40

Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

  • EPSS 0.23%
  • Published 12.03.2015 10:59:09
  • Last modified 12.04.2025 10:46:40

Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.

  • EPSS 5.41%
  • Published 12.03.2015 10:59:05
  • Last modified 12.04.2025 10:46:40

IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.

Exploit
  • EPSS 4.8%
  • Published 11.03.2015 01:59:00
  • Last modified 12.04.2025 10:46:40

Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via c...

  • EPSS 18.72%
  • Published 08.03.2015 02:59:00
  • Last modified 12.04.2025 10:46:40

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script ha...

  • EPSS 10.38%
  • Published 12.02.2015 16:59:07
  • Last modified 12.04.2025 10:46:40

Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.

  • EPSS 0.48%
  • Published 30.01.2015 11:59:48
  • Last modified 12.04.2025 10:46:40

Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP...

  • EPSS 0.16%
  • Published 30.01.2015 11:59:47
  • Last modified 12.04.2025 10:46:40

The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the Gatekeeper protection mechanism by leveraging access to a revoked Developer ID certificate f...

  • EPSS 1.68%
  • Published 30.01.2015 11:59:46
  • Last modified 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arbitrary code in a privileged context via a crafted app.