Vulnerability index

Browse CVEs

157 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Mac Os X HIGH 7.2
CVE-2015-5888

The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged exe…

Fix: after 10.10.5
Fix from $1,950 2015-10-09
Mac Os X MEDIUM 6.8
CVE-2015-5849

The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Safari MEDIUM 5.0
CVE-2015-3801

The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intend…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Mac Os X HIGH 9.3
CVE-2015-5784EPSS 9%

runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly drop privileges, which allows at…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Iphone Os MEDIUM 5.8
CVE-2015-5770

MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to r…

Fix: after 8.4
Fix from $1,600 2015-08-17
Mac Os X HIGH 7.2
CVE-2015-3772

IOFireWireFamily in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified …

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Mac Os X HIGH 7.2
CVE-2015-3767

udf in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via a m…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Mac Os X HIGH 7.2
CVE-2015-3761

The kernel in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unsp…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Safari MEDIUM 6.8
CVE-2015-3727

WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly re…

Fix: after 10.10.3
Fix from $1,600 2015-07-03
Mac Os X HIGH 9.3
CVE-2015-3704EPSS 9%

runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows at…

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Mac Os X HIGH 7.2
CVE-2015-3673EPSS 6%

Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Safari MEDIUM 6.8
CVE-2015-3659

The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple i…

Fix: after 10.10.3
Fix from $1,600 2015-07-03
Xcode MEDIUM 5.0
CVE-2015-3027

Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointe…

Fix: after 6.2
Fix from $1,600 2015-04-10
Iphone Os MEDIUM 6.9
CVE-2015-1117

The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2014-8831

security_taskgate in Apple OS X before 10.10.2 allows attackers to read group-ACL-restricted keychain items of arbitrary apps via a crafted app with …

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X HIGH 7.5
CVE-2014-8828

Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that includes a com.apple.sandbox segme…

Fix: after 10.9.5
Fix from $1,950 2015-01-30
Iphone Os MEDIUM 5.0
CVE-2014-4496

The mach_port_kobject interface in the kernel in Apple iOS before 8.1.3 and Apple TV before 7.0.3 does not properly restrict kernel-address and heap-…

Fix: after 8.1.2
Fix from $1,600 2015-01-30
Iphone Os HIGH 10.0
CVE-2014-4495

The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memor…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Iphone Os HIGH 7.5
CVE-2014-4493

The app-installation functionality in MobileInstallation in Apple iOS before 8.1.3 allows attackers to obtain control of the local app container by l…

Fix: after 8.1.2
Fix from $1,950 2015-01-30
Iphone Os HIGH 7.5
CVE-2014-4457

The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intend…

Fix: after 8.1
Fix from $1,950 2014-11-18
Iphone Os HIGH 7.2
CVE-2014-4451

Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lo…

Fix: after 8.1
Fix from $1,950 2014-11-18
Mac Os X HIGH 7.5
CVE-2014-4427

App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.

Fix: after 10.9.5
Fix from $1,950 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4437

LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application that specifies a crafted handle…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4441

NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attacker…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Iphone Os MEDIUM 6.9
CVE-2014-4368

The Accessibility subsystem in Apple iOS before 8 allows attackers to interfere with screen locking via vectors related to AssistiveTouch events.

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.8
CVE-2014-4354

Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass intended access restrictions vi…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Mac Os X HIGH 10.0
CVE-2014-1373

Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitr…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1376

Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call, which allows attackers to execute arbitrary code…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1381

Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2014-07-01
Tvos MEDIUM 5.5
CVE-2014-1383

Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspeci…

Fix: after 6.1.1
Fix from $1,600 2014-07-01