Vulnerabilities > Apple

DATE CVE VULNERABILITY TITLE RISK
2015-12-11 CVE-2015-7071 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
The File Bookmark component in Apple OS X before 10.11.2 allows attackers to bypass a sandbox protection mechanism for app scoped bookmarks via a crafted pathname.
network
low complexity
apple CWE-264
critical
10.0
2015-12-11 CVE-2015-7070 Unspecified vulnerability in Apple Iphone OS
Mobile Replayer in GPUTools Framework in Apple iOS before 9.2 allows attackers to execute arbitrary code in a privileged context via an app that provides a crafted pathname, a different vulnerability than CVE-2015-7069.
network
apple
critical
9.3
2015-12-11 CVE-2015-7069 Unspecified vulnerability in Apple Iphone OS
Mobile Replayer in GPUTools Framework in Apple iOS before 9.2 allows attackers to execute arbitrary code in a privileged context via an app that provides a crafted pathname, a different vulnerability than CVE-2015-7070.
network
apple
critical
9.3
2015-12-11 CVE-2015-7068 NULL Pointer Dereference vulnerability in Apple products
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.
network
apple CWE-476
critical
9.3
2015-12-11 CVE-2015-7067 Unspecified vulnerability in Apple mac OS X
IOThunderboltFamily in Apple OS X before 10.11.2 allows local users to cause a denial of service (NULL pointer dereference) via an unspecified userclient type.
local
low complexity
apple
2.1
2015-12-11 CVE-2015-7066 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7064.
network
apple CWE-119
6.8
2015-12-11 CVE-2015-7065 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS, mac OS X and Tvos
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
network
apple CWE-119
6.8
2015-12-11 CVE-2015-7064 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7066.
network
apple CWE-119
6.8
2015-12-11 CVE-2015-7063 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a crafted pathname.
local
low complexity
apple CWE-264
7.2
2015-12-11 CVE-2015-7062 Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS and mac OS X
Apple OS X before 10.11.2 and tvOS before 9.1 allow local users to bypass intended configuration-profile installation restrictions via unspecified vectors.
local
low complexity
apple CWE-264
4.6