Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-5835 | 1 Apple | 1 Iphone Os | 2016-12-21 | 4.3 MEDIUM | N/A |
Apple iOS before 9 allows attackers to obtain sensitive information about inter-app communication via a crafted app that conducts an interception attack involving an unspecified URL scheme. | |||||
CVE-2015-5842 | 1 Apple | 3 Iphone Os, Mac Os X, Watchos | 2016-12-21 | 2.1 LOW | N/A |
XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors. | |||||
CVE-2015-5851 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-21 | 2.1 LOW | N/A |
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack. | |||||
CVE-2015-5855 | 1 Apple | 2 Iphone Os, Watchos | 2016-12-21 | 4.3 MEDIUM | N/A |
Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Center app. | |||||
CVE-2015-5858 | 1 Apple | 2 Iphone Os, Watchos | 2016-12-21 | 5.0 MEDIUM | N/A |
The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL. | |||||
CVE-2015-5860 | 1 Apple | 2 Iphone Os, Watchos | 2016-12-21 | 5.0 MEDIUM | N/A |
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site. | |||||
CVE-2015-5863 | 1 Apple | 3 Iphone Os, Mac Os X, Watchos | 2016-12-21 | 2.1 LOW | N/A |
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors. | |||||
CVE-2015-5880 | 1 Apple | 1 Iphone Os | 2016-12-21 | 4.3 MEDIUM | N/A |
CoreAnimation in Apple iOS before 9 allows attackers to bypass intended IOSurface restrictions and obtain screen-framebuffer access via a crafted background app. | |||||
CVE-2015-5885 | 1 Apple | 3 Iphone Os, Mac Os X, Watchos | 2016-12-21 | 5.0 MEDIUM | N/A |
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain. | |||||
CVE-2015-5892 | 1 Apple | 1 Iphone Os | 2016-12-21 | 2.1 LOW | N/A |
Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state. | |||||
CVE-2015-5898 | 1 Apple | 2 Iphone Os, Watchos | 2016-12-21 | 2.1 LOW | N/A |
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID. | |||||
CVE-2015-5906 | 1 Apple | 1 Iphone Os | 2016-12-21 | 5.0 MEDIUM | N/A |
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that character. | |||||
CVE-2015-5909 | 1 Apple | 1 Xcode | 2016-12-21 | 5.0 MEDIUM | N/A |
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery. | |||||
CVE-2015-5910 | 1 Apple | 1 Xcode | 2016-12-21 | 3.3 LOW | N/A |
IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
CVE-2015-5916 | 1 Apple | 2 Iphone Os, Watchos | 2016-12-21 | 4.3 MEDIUM | N/A |
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature. | |||||
CVE-2015-5921 | 1 Apple | 1 Iphone Os | 2016-12-21 | 4.3 MEDIUM | N/A |
WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-6830 | 1 Phpmyadmin | 1 Phpmyadmin | 2016-12-21 | 5.0 MEDIUM | N/A |
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha. | |||||
CVE-2015-7327 | 1 Mozilla | 1 Firefox | 2016-12-21 | 4.3 MEDIUM | N/A |
Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls. | |||||
CVE-2016-7888 | 1 Adobe | 1 Digital Editions | 2016-12-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak. | |||||
CVE-2015-4519 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-21 | 4.3 MEDIUM | N/A |
Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element. |