Vulnerabilities > Apple > MAC OS X > Critical

DATE CVE VULNERABILITY TITLE RISK
2015-03-13 CVE-2015-0341 Use After Free Remote Code Execution vulnerability in Adobe Flash Player
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0342.
network
low complexity
adobe linux apple microsoft
critical
10.0
2015-03-13 CVE-2015-0339 Resource Management Errors vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0333, and CVE-2015-0335.
network
low complexity
adobe linux apple microsoft CWE-399
critical
10.0
2015-03-13 CVE-2015-0338 Remote Integer Overflow vulnerability in Adobe Flash Player
Integer overflow in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
adobe linux apple microsoft
critical
10.0
2015-03-13 CVE-2015-0336 Type Confusion Remote Code Execution vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.
network
adobe apple microsoft linux
critical
9.3
2015-03-13 CVE-2015-0335 Resource Management Errors vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0333, and CVE-2015-0339.
network
low complexity
adobe apple microsoft linux CWE-399
critical
10.0
2015-03-13 CVE-2015-0334 Type Confusion Remote Code Execution vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0336.
network
adobe apple microsoft linux
critical
9.3
2015-03-13 CVE-2015-0333 Resource Management Errors vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0335, and CVE-2015-0339.
network
low complexity
adobe apple microsoft linux CWE-399
critical
10.0
2015-03-13 CVE-2015-0332 Memory Corruption vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0333, CVE-2015-0335, and CVE-2015-0339.
network
low complexity
adobe apple microsoft linux
critical
10.0
2015-03-12 CVE-2015-1066 Numeric Errors vulnerability in Apple mac OS X
Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
network
low complexity
apple CWE-189
critical
10.0
2015-03-12 CVE-2015-1061 Code Injection vulnerability in Apple Iphone OS, mac OS X and Tvos
IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.
network
apple CWE-94
critical
9.3