Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari MEDIUM 6.8
CVE-2015-1074

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Safari MEDIUM 6.8
CVE-2015-1073

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Safari MEDIUM 6.8
CVE-2015-1072

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Safari MEDIUM 6.8
CVE-2015-1071

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Safari MEDIUM 6.8
CVE-2015-1070

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Safari MEDIUM 6.8
CVE-2015-1069

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Safari MEDIUM 6.8
CVE-2015-1068

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Mac Os X HIGH 10.0
CVE-2015-1066

Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafte…

Fix: after 10.10.2
Fix from $1,950 2015-03-12
Mac Os X MEDIUM 5.4
CVE-2015-1065

Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbi…

Fix: after 10.10.2
Fix from $1,600 2015-03-12
Iphone Os HIGH 7.8
CVE-2015-1063

CoreTelephony in Apple iOS before 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a Class …

Fix: after 8.1.3
Fix from $1,950 2015-03-12
Tvos MEDIUM 5.0
CVE-2015-1062

MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create fol…

Fix: after 8.1.3
Fix from $1,600 2015-03-12
Tvos HIGH 9.3
CVE-2015-1061

IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged con…

Fix: after 10.10.2
Fix from $1,950 2015-03-12
Cups MEDIUM 6.8
CVE-2014-9679

Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via…

Fix: after 2.0.1
Fix from $1,600 2015-02-19
Iphone Os MEDIUM 6.8
CVE-2014-8840

The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirectio…

Fix: after 8.1.2
Fix from $1,600 2015-01-30
Mac Os X MEDIUM 5.0
CVE-2014-8839

Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to di…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X HIGH 9.3
CVE-2014-8837

Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arbitrary code in a privileged c…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 10.0
CVE-2014-8836

The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (ar…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 9.3
CVE-2014-8835EPSS 8%

The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type,…

No fix yet
Fix from $1,950 2015-01-30
Mac Os X MEDIUM 5.0
CVE-2014-8831

security_taskgate in Apple OS X before 10.10.2 allows attackers to read group-ACL-restricted keychain items of arbitrary apps via a crafted app with …

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X MEDIUM 6.8
CVE-2014-8830

Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X HIGH 7.5
CVE-2014-8829

SceneKit in Apple OS X before 10.10.2 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 7.5
CVE-2014-8828

Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that includes a com.apple.sandbox segme…

Fix: after 10.9.5
Fix from $1,950 2015-01-30
Mac Os X MEDIUM 5.0
CVE-2014-8826EPSS 9%

LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection m…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X HIGH 7.2
CVE-2014-8825

The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows loc…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 10.0
CVE-2014-8824

The kernel in Apple OS X before 10.10.2 does not properly validate IODataQueue object metadata fields, which allows attackers to execute arbitrary co…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 10.0
CVE-2014-8822

IOHIDFamily in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a kernel context or cause a denial of service (write to kernel…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 7.2
CVE-2014-8821

The Intel Graphics Driver in Apple OS X before 10.10.2 allows local users to gain privileges via unspecified vectors, a different vulnerability than …

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 7.2
CVE-2014-8820

The Intel Graphics Driver in Apple OS X before 10.10.2 allows local users to gain privileges via unspecified vectors, a different vulnerability than …

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 7.2
CVE-2014-8819

The Intel Graphics Driver in Apple OS X before 10.10.2 allows local users to gain privileges via unspecified vectors, a different vulnerability than …

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 10.0
CVE-2014-8817

coresymbolicationd in CoreSymbolication in Apple OS X before 10.10.2 does not verify that expected data types are present in XPC messages, which allo…

Fix: after 10.10.1
Fix from $1,950 2015-01-30