Unknown · CVSS Not scored
Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91854.
Published Jul 6, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546.
Published Jul 4, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.
Published Jul 5, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file.
Published Jul 20, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Samsung SBeam allows remote attackers to read arbitrary images by leveraging an NFC connection to access the HTTP server on port 15000.
Published Jul 6, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.
Published Jul 25, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcelable object in a serialized MethodSpec object.
Published Jul 6, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors.
Published Jul 6, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Hospira LifeCare PCA Infusion System before 7.0 stores private keys and certificates, which has unspecified impact and attack vectors.
Published Jul 6, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP packets.
Published Jul 6, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.
Published Jul 21, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
Published Jul 3, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.
Published Jul 21, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.
Published Jul 21, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The kernel in Apple iOS before 8.4 and OS X before 10.10.4 does not properly handle HFS parameters, which allows attackers to obtain sensitive memory-layout information via a crafted app.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The code-signing implementation in Apple OS X before 10.10.4 does not properly consider libraries that are external to an application bundle, which allows attackers to bypass intended launch restrictions via a crafted library.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh operation, and consequently cause a visit to an arbitrary web site, via a crafted HTML e-mail message.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3706.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apple OS X before 10.10.4 does not properly consider custom resource rules during app signature verification, which allows attackers to bypass intended launch restrictions via a modified app.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
TrueTypeScaler in FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3694.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
QuickTime in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted movie file.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause a denial of service (memory corruption), by triggering certain patterns of access to memory locations.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Race condition in kext tools in Apple OS X before 10.10.4 allows local users to bypass intended signature requirements for kernel extensions by leveraging improper pathname validation.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, which allows attackers to obtain sensitive memory-layout information via a crafted app.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The WiFi Connectivity feature in Apple iOS before 8.4 allows remote Wi-Fi access points to trigger an automatic association, with an arbitrary security type, by operating with a recognized ESSID within an 802.11 network's coverage area.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Application Store in Apple iOS before 8.4 does not ensure the uniqueness of bundle IDs, which allows attackers to cause a denial of service (ID collision and launch outage) via a crafted universal provisioning profile app.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The NVIDIA graphics driver in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds write) via a crafted app.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging root privileges.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, and CVE-2015-3702.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3705.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3701, and CVE-2015-3702.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ImageIO in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Telephony subsystem in Apple iOS before 8.4 allows physically proximate attackers to execute arbitrary code via a crafted (1) SIM or (2) UIM card.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3702.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3719.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages control of a function pointer.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
systemstatsd in the System Stats subsystem in Apple OS X before 10.10.4 does not properly interpret data types encountered in interprocess communication, which allows attackers to execute arbitrary code with systemstatsd privileges via a crafted app, related to a "type confusion" issue.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a crafted app that conducts a symlink attack.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The NTFS implementation in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
Published Jul 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3701.
Published Jul 3, 2015 · Updated Aug 6, 2024