Vulnerabilities > Apple > MAC OS X > 10.5.6

DATE CVE VULNERABILITY TITLE RISK
2015-07-03 CVE-2015-3683 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
The Bluetooth HCI interface implementation in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
network
apple CWE-119
critical
9.3
2015-07-03 CVE-2015-3682 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015-3681.
network
apple CWE-119
6.8
2015-07-03 CVE-2015-3681 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015-3682.
network
apple CWE-119
6.8
2015-07-03 CVE-2015-3680 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3681, and CVE-2015-3682.
network
apple CWE-119
6.8
2015-07-03 CVE-2015-3679 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3680, CVE-2015-3681, and CVE-2015-3682.
network
apple CWE-119
6.8
2015-07-03 CVE-2015-3678 Command Injection vulnerability in Apple mac OS X
AppleThunderboltEDMService in Apple OS X before 10.10.4 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified Thunderbolt commands.
local
low complexity
apple CWE-77
7.2
2015-07-03 CVE-2015-3677 Information Exposure vulnerability in Apple mac OS X
The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
network
apple CWE-200
4.3
2015-07-03 CVE-2015-3676 Information Exposure vulnerability in Apple mac OS X
AppleGraphicsControl in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information via a crafted app.
network
apple CWE-200
4.3
2015-07-03 CVE-2015-3675 Improper Access Control vulnerability in Apple mac OS X
The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attackers to bypass HTTP authentication via a crafted URL.
network
low complexity
apple CWE-284
5.0
2015-07-03 CVE-2015-3674 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
afpserver in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
network
low complexity
apple CWE-119
7.5