Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-09-18 CVE-2015-5912 Code vulnerability in Apple Iphone OS and mac OS X
The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
network
low complexity
apple CWE-17
5.0
2015-09-18 CVE-2015-5909 Information Exposure vulnerability in Apple Xcode
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.
network
low complexity
apple CWE-200
5.0
2015-09-18 CVE-2015-5906 Information Exposure vulnerability in Apple Iphone OS
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that character.
network
low complexity
apple CWE-200
5.0
2015-09-18 CVE-2015-5905 7PK - Security Features vulnerability in Apple Iphone OS
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.
network
low complexity
apple CWE-254
5.0
2015-09-18 CVE-2015-5904 7PK - Security Features vulnerability in Apple Iphone OS
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.
network
apple CWE-254
4.3
2015-09-18 CVE-2015-5885 Information Exposure vulnerability in Apple Iphone OS, mac OS X and Watchos
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
network
low complexity
apple CWE-200
5.0
2015-09-18 CVE-2015-5880 Information Exposure vulnerability in Apple Iphone OS
CoreAnimation in Apple iOS before 9 allows attackers to bypass intended IOSurface restrictions and obtain screen-framebuffer access via a crafted background app.
network
apple CWE-200
4.3
2015-09-18 CVE-2015-5879 Improper Input Validation vulnerability in Apple Iphone OS and mac OS X
XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-number protection mechanism and cause a denial of service (TCP connection disruption) via a crafted header.
network
low complexity
apple CWE-20
5.0
2015-09-18 CVE-2015-5862 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS, mac OS X and Watchos
The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.
network
apple CWE-119
4.3
2015-09-18 CVE-2015-5860 Information Exposure vulnerability in Apple Iphone OS and Watchos
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.
network
low complexity
apple CWE-200
5.0