Apple

macOS X

3207 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 30.01.2015 11:59:27
  • Last modified 12.04.2025 10:46:40

The CPU Software in Apple OS X before 10.10.2 allows physically proximate attackers to modify firmware during the EFI update process by inserting a Thunderbolt device with crafted code in an Option ROM, aka the "Thunderstrike" issue.

  • EPSS 0.06%
  • Published 30.01.2015 11:59:27
  • Last modified 12.04.2025 10:46:40

The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file.

  • EPSS 1.1%
  • Published 30.01.2015 11:59:26
  • Last modified 12.04.2025 10:46:40

Integer signedness error in IOBluetoothFamily in the Bluetooth implementation in Apple OS X before 10.10 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (write to kernel memory) via a crafted app.

  • EPSS 0.83%
  • Published 30.01.2015 11:59:24
  • Last modified 12.04.2025 10:46:40

The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restric...

Exploit
  • EPSS 19.46%
  • Published 30.01.2015 11:59:21
  • Last modified 12.04.2025 10:46:40

libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC mes...

  • EPSS 1.02%
  • Published 30.01.2015 11:59:20
  • Last modified 12.04.2025 10:46:40

IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly initialize event queues, which allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer...

  • EPSS 0.52%
  • Published 30.01.2015 11:59:20
  • Last modified 12.04.2025 10:46:40

The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addresses within an OSBundleMachOHeaders key in a response, which makes it easier for attackers to bypass ...

  • EPSS 1.8%
  • Published 30.01.2015 11:59:19
  • Last modified 12.04.2025 10:46:40

IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly validate resource-queue metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

  • EPSS 2.42%
  • Published 30.01.2015 11:59:18
  • Last modified 12.04.2025 10:46:40

Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows attackers to execute arbitrary code in a privileged context via a crafted app.

  • EPSS 1.02%
  • Published 30.01.2015 11:59:17
  • Last modified 12.04.2025 10:46:40

IOAcceleratorFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly handle resource lists and IOService userclient types, which allows attackers to execute arbitrary code or cause a denial of service ...