Vulnerabilities > Apple > MAC OS X > Low

DATE CVE VULNERABILITY TITLE RISK
2015-10-09 CVE-2015-5864 Information Exposure vulnerability in Apple mac OS X
IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
local
low complexity
apple CWE-200
2.1
2015-10-09 CVE-2015-5870 Information Exposure vulnerability in Apple mac OS X
The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.
local
low complexity
apple CWE-200
2.1
2015-10-09 CVE-2015-5875 Cross-site Scripting vulnerability in Apple mac OS X
Cross-site scripting (XSS) vulnerability in Notes in Apple OS X before 10.11 allows local users to inject arbitrary web script or HTML via crafted text.
local
low complexity
apple CWE-79
2.1
2015-10-09 CVE-2015-5878 Information Exposure vulnerability in Apple mac OS X
Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
apple CWE-200
2.1
2015-10-09 CVE-2015-5884 Information Exposure vulnerability in Apple mac OS X
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.
low complexity
apple CWE-200
3.3
2015-10-09 CVE-2015-5893 Information Exposure vulnerability in Apple mac OS X
SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
local
low complexity
apple CWE-200
2.1
2015-10-09 CVE-2015-5901 Information Exposure vulnerability in Apple mac OS X
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.
local
low complexity
apple CWE-200
2.1
2015-09-18 CVE-2015-5863 Information Exposure vulnerability in Apple Iphone OS, mac OS X and Watchos
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
local
low complexity
apple CWE-200
2.1
2015-09-18 CVE-2015-5869 Improper Input Validation vulnerability in Apple Iphone OS, mac OS X and Watchos
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
low complexity
apple CWE-20
3.3
2015-09-18 CVE-2015-5851 Information Exposure vulnerability in Apple Iphone OS and mac OS X
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.
local
low complexity
apple CWE-200
2.1