Vulnerabilities > Apple > High

DATE CVE VULNERABILITY TITLE RISK
2015-04-10 CVE-2015-1143 Multiple Security vulnerability in Apple Mac OS X Prior to 10.10.3
LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue.
local
low complexity
apple
7.2
2015-04-10 CVE-2015-1140 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors.
local
low complexity
apple CWE-119
7.2
2015-04-10 CVE-2015-1137 Multiple Security vulnerability in Apple Mac OS X Prior to 10.10.3
The NVIDIA graphics driver in Apple OS X before 10.10.3 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via an unspecified IOService userclient type.
local
low complexity
apple
7.2
2015-04-10 CVE-2015-1135 Improper Input Validation vulnerability in Apple mac OS X
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1134.
local
low complexity
apple CWE-20
7.2
2015-04-10 CVE-2015-1134 Improper Input Validation vulnerability in Apple mac OS X
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1135.
local
low complexity
apple CWE-20
7.2
2015-04-10 CVE-2015-1133 Improper Input Validation vulnerability in Apple mac OS X
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1134, and CVE-2015-1135.
local
low complexity
apple CWE-20
7.2
2015-04-10 CVE-2015-1131 Improper Input Validation vulnerability in Apple mac OS X
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1132, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
local
low complexity
apple CWE-20
7.2
2015-04-10 CVE-2015-1130 7PK - Security Features vulnerability in Apple mac OS X
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
local
low complexity
apple CWE-254
7.2
2015-04-10 CVE-2015-1103 Improper Input Validation vulnerability in Apple Iphone OS, mac OS X and Tvos
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing changes in response to ICMP_REDIRECT messages, which allows remote attackers to cause a denial of service (network outage) or obtain sensitive packet-content information via a crafted ICMP packet.
network
low complexity
apple CWE-20
7.5
2015-04-10 CVE-2015-1102 Improper Input Validation vulnerability in Apple Iphone OS, mac OS X and Tvos
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly handle TCP headers, which allows man-in-the-middle attackers to cause a denial of service via unspecified vectors.
network
apple CWE-20
7.1