Page 132 of 2057 results (0.017 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

21 Oct 2015 — ImageIO in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image. ImageIO en Apple OS X en versiones anteriores a 10.11.1 permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (corrupción de memoria) a través de metadatos manipulados en una imagen. OS X El Capitan 10.11.1 and Security Update 2015-007 are now available and address memory corruption, code execution, an... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

21 Oct 2015 — SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a crafted app. SecurityAgent en Apple OS X en versiones anteriores a 10.11.1 no previene que clics sintéticos alcancen ventanas del llavero, lo que permite a atacantes eludir las restricciones destinadas al acceso a través de una aplicación manipulada. OS X El Capitan 10.11.1 and Security Update 2015-007 are now available and address m... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-254: 7PK - Security Features •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

21 Oct 2015 — CoreText in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file. CoreText en Apple OS X en versiones anteriores a 10.11.1 permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (corrupción de memoria) a través de un archivo de fuente manipulado. OS X El Capitan 10.11.1 and Security Update 2015-007 are now available and address memory corruption, code execution, and various o... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

21 Oct 2015 — The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters. El subsistema Sandbox en Apple OS X en versiones anteriores a 10.11.1 permite a usuarios locales obtener privilegios a través de vectores que involucran parámetros NVRAM. OS X El Capitan 10.11.1 and Security Update 2015-007 are now available and address memory corruption, code execution, and various other vulnerabilities. • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-20: Improper Input Validation CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

21 Oct 2015 — Double free vulnerability in Apple iOS before 9.1 and OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that accesses AtomicBufferedFile descriptors. Vulnerabilidad de liberación doble en Apple iOS en versiones anteriores a 9.1 y OS X en versiones anteriores a 10.11.1 permite a atacantes escribir en archivos arbitrarios a través de una aplicación manipulada que accede a descriptores AtomicBufferedFile. iOS 9.1 is now available and addresses arbitrary code execution, cookies ... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

21 Oct 2015 — libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that conducts an unspecified symlink attack. libarchive en Apple OS X en versiones anteriores a 10.11.1 permite a atacantes escribir en archivos arbitrarios a través de una aplicación manipulada que lleva a cabo un ataque de enlace simbólico no especificado. OS X El Capitan 10.11.1 and Security Update 2015-007 are now available and address memory corruption, code execution, and various other vulnerabilitie... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-284: Improper Access Control •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

21 Oct 2015 — Apple Type Services (ATS) in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web page. Apple Type Services (ATS) en Apple OS X en versiones anteriores a 10.11.1 permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (corrupción de memoria y caída de aplicación) a través de una página web manipulada. OS X El Capitan 10.11.1 and Security Update 2015-007 are now... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

21 Oct 2015 — The File Bookmark component in Apple OS X before 10.11.1 allows local users to cause a denial of service (application crash) via crafted bookmark metadata in a folder. El componente File Bookmark en Apple OS X en versiones anteriores a 10.11.1 permite a usuarios locales provocar una denegación de servicio (caída de aplicación) a través de metadatos de marcador manipulados en una carpeta. OS X El Capitan 10.11.1 and Security Update 2015-007 are now available and address memory corruption, code execution, and... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-20: Improper Input Validation •

CVSS: 7.1EPSS: 0%CPEs: 2EXPL: 0

21 Oct 2015 — The kernel in Apple iOS before 9.1 and OS X before 10.11.1 mishandles reuse of virtual memory, which allows attackers to cause a denial of service via a crafted app. El kernel en Apple iOS en versiones anteriores a 9.1 y OS X en versiones anteriores a 10.11.1 no maneja correctamente la reutilización de la memoria virtual, lo que permite a atacantes provocar una denegación de servicio a través de una aplicación manipulada. iOS 9.1 is now available and addresses arbitrary code execution, cookies being overwri... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html • CWE-399: Resource Management Errors •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

21 Oct 2015 — coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure, which allows attackers to execute arbitrary code via a crafted app. coreaudiod en Audio en Apple OS X en versiones anteriores a 10.11.1 no inicializa una estructura de datos sin especificar, lo que permite a atacantes ejecutar código arbitrario a través de una aplicación manipulada. com.apple.audio.coreaudiod is reachable from various sandboxes including the Safari renderer. coreaudiod is sandboxed and runs a... • https://packetstorm.news/files/id/135422 • CWE-264: Permissions, Privileges, and Access Controls •