Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Filtered by product Watchos
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-5903 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 10.0 HIGH N/A
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.
CVE-2015-5899 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 7.2 HIGH N/A
libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-5898 1 Apple 2 Iphone Os, Watchos 2016-12-22 2.1 LOW N/A
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
CVE-2015-5896 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 7.2 HIGH N/A
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.
CVE-2015-5885 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 5.0 MEDIUM N/A
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
CVE-2015-5882 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 7.2 HIGH N/A
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.
CVE-2015-5876 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 9.3 HIGH N/A
dyld in Dev Tools in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
CVE-2015-5874 1 Apple 4 Iphone Os, Itunes, Mac Os X and 1 more 2016-12-22 7.5 HIGH N/A
CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
CVE-2015-5869 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 3.3 LOW N/A
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
CVE-2015-5868 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 7.2 HIGH N/A
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.
CVE-2015-5867 1 Apple 2 Iphone Os, Watchos 2016-12-22 9.3 HIGH N/A
IOHIDFamily in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
CVE-2015-5863 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 2.1 LOW N/A
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
CVE-2015-5862 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 4.3 MEDIUM N/A
The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.
CVE-2015-5860 1 Apple 2 Iphone Os, Watchos 2016-12-22 5.0 MEDIUM N/A
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.
CVE-2015-5858 1 Apple 2 Iphone Os, Watchos 2016-12-22 5.0 MEDIUM N/A
The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.
CVE-2015-5855 1 Apple 2 Iphone Os, Watchos 2016-12-22 4.3 MEDIUM N/A
Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Center app.
CVE-2015-5848 1 Apple 2 Iphone Os, Watchos 2016-12-22 7.2 HIGH N/A
IOAcceleratorFamily in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-5847 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 7.2 HIGH N/A
The Disk Images component in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-5846 1 Apple 2 Iphone Os, Watchos 2016-12-22 9.3 HIGH N/A
IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5844 and CVE-2015-5845.
CVE-2015-5845 1 Apple 2 Iphone Os, Watchos 2016-12-22 9.3 HIGH N/A
IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5844 and CVE-2015-5846.
CVE-2015-5844 1 Apple 2 Iphone Os, Watchos 2016-12-22 9.3 HIGH N/A
IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5845 and CVE-2015-5846.
CVE-2015-5843 1 Apple 2 Iphone Os, Watchos 2016-12-22 7.2 HIGH N/A
IOMobileFrameBuffer in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-5840 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 5.0 MEDIUM N/A
The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial of service (overflow fault and app crash) via crafted data.
CVE-2015-5839 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 5.0 MEDIUM N/A
dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app that places a crafted signature in an executable file.
CVE-2015-5837 1 Apple 2 Iphone Os, Watchos 2016-12-22 4.3 MEDIUM N/A
PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app.
CVE-2015-5834 1 Apple 2 Iphone Os, Watchos 2016-12-22 4.3 MEDIUM N/A
IOAcceleratorFamily in Apple iOS before 9 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
CVE-2015-5829 1 Apple 2 Iphone Os, Watchos 2016-12-22 6.8 MEDIUM N/A
Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file.
CVE-2015-5824 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 4.3 MEDIUM N/A
The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2015-5841 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-22 5.0 MEDIUM N/A
The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
CVE-2015-5523 4 Apple, Canonical, Debian and 1 more 6 Iphone Os, Mac Os X, Watchos and 3 more 2016-12-08 4.3 MEDIUM N/A
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
CVE-2015-5522 4 Apple, Canonical, Debian and 1 more 6 Iphone Os, Mac Os X, Watchos and 3 more 2016-12-08 6.8 MEDIUM N/A
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
CVE-2013-3951 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-08 4.6 MEDIUM N/A
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.
CVE-2015-7113 1 Apple 2 Iphone Os, Watchos 2016-12-07 10.0 HIGH N/A
The LaunchServices component in Apple iOS before 9.2 and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a malformed plist.
CVE-2016-1788 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-03 2.6 LOW 5.9 MEDIUM
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages.
CVE-2016-1761 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-03 10.0 HIGH 9.8 CRITICAL
libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
CVE-2016-1842 1 Apple 3 Iphone Os, Mac Os X, Watchos 2016-12-01 5.0 MEDIUM 7.5 HIGH
MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.