Apple

macOS X

3207 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.91%
  • Veröffentlicht 14.08.2015 18:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

Exploit
  • EPSS 5.03%
  • Veröffentlicht 11.08.2015 14:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

Exploit
  • EPSS 6.47%
  • Veröffentlicht 11.08.2015 14:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.

  • EPSS 10.32%
  • Veröffentlicht 20.07.2015 23:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote...

  • EPSS 12.98%
  • Veröffentlicht 20.07.2015 23:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending...

  • EPSS 0.94%
  • Veröffentlicht 03.07.2015 02:00:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web s...

  • EPSS 0.58%
  • Veröffentlicht 03.07.2015 02:00:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The kernel in Apple iOS before 8.4 and OS X before 10.10.4 does not properly handle HFS parameters, which allows attackers to obtain sensitive memory-layout information via a crafted app.

  • EPSS 0.3%
  • Veröffentlicht 03.07.2015 02:00:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, which allows attackers to obtain sensitive memory-layout information via a crafted app.

  • EPSS 1.4%
  • Veröffentlicht 03.07.2015 02:00:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

TrueTypeScaler in FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3694.

  • EPSS 1.18%
  • Veröffentlicht 03.07.2015 02:00:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

systemstatsd in the System Stats subsystem in Apple OS X before 10.10.4 does not properly interpret data types encountered in interprocess communication, which allows attackers to execute arbitrary code with systemstatsd privileges via a crafted app,...