CVE-2015-7003 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7003
21 Oct 2015 — coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure, which allows attackers to execute arbitrary code via a crafted app. coreaudiod en Audio en Apple OS X en versiones anteriores a 10.11.1 no inicializa una estructura de datos sin especificar, lo que permite a atacantes ejecutar código arbitrario a través de una aplicación manipulada. com.apple.audio.coreaudiod is reachable from various sandboxes including the Safari renderer. coreaudiod is sandboxed and runs a... • https://packetstorm.news/files/id/135422 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2015-7006 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7006
21 Oct 2015 — Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO archive. Vulnerabilidad de salto de directorio en el componente BOM (también conocido como Bill of Materials) en Apple iOS en versiones anteriores a 9.1, OS X en versiones anteriores a 10.11.1 y watchOS en versiones anteriores a 2.0.1 permite a atacantes remotos ejecutar código arbitrario a t... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2015-7007 – Apple Safari - User-Assisted Applescript Exec Attack
https://notcve.org/view.php?id=CVE-2015-7007
21 Oct 2015 — Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors. Script Editor en Apple OS X en versiones anteriores a 10.11.1 permite a atacantes remotos eludir un requisito destinado a la confirmación de usuario para la ejecución de AppleScript a través de vectores no especificados. In versions of Mac OS X before 10.11.1, the applescript:// URL scheme is provided, which opens the provided script in the... • https://packetstorm.news/files/id/134072 •
CVE-2015-7008 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7008
21 Oct 2015 — FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018. FontParser en Apple iOS en versiones anteriores a 9.1 y OS X en versiones anteriores a 10.11.1 permite a atacantes remotos ejecutar código arbitrario o provoca... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-7009 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7009
21 Oct 2015 — FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7010, and CVE-2015-7018. FontParser en Apple iOS en versiones anteriores a 9.1 y OS X en versiones anteriores a 10.11.1 permite a atacantes remotos ejecutar código arbitrario o provoca... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-7010 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7010
21 Oct 2015 — FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7018. FontParser en Apple iOS en versiones anteriores a 9.1 y OS X en versiones anteriores a 10.11.1 permite a atacantes remotos ejecutar código arbitrario o provoca... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-7013 – Apple Security Advisory 2015-10-21-3
https://notcve.org/view.php?id=CVE-2015-7013
21 Oct 2015 — WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5. WebKit, como se utiliza en Apple Safari en versiones anteriores a 9.0.1 y iTunes en versiones anteriores a 12.3.1, permite a atacantes remotos ejecutar código arbitrario o provocar una den... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-7021 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7021
21 Oct 2015 — The Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to gain privileges or cause a denial of service (kernel memory corruption) via unspecified vectors. El subsistema Graphics Drivers en Apple OS X en versiones anteriores a 10.11.1 permite a usuarios locales obtener privilegios o provocar una denegación de servicio (corrupción de memoria del kernel) a través de vectores no especificados. OS X El Capitan 10.11.1 and Security Update 2015-007 are now available and address memory corru... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-7023 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7023
21 Oct 2015 — CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors. CFNetwork en Apple iOS en versiones anteriores a 9.1 y OS X en versiones anteriores a 10.11.1 no considera adecuadamente la distinción de mayúsculas frente a minúsculas durante el análisis de cookie, lo que permite a servidores web remotos sobrescribir cookies a través de vectores n... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html • CWE-17: DEPRECATED: Code •
CVE-2015-7035 – Apple Security Advisory 2015-10-21-4
https://notcve.org/view.php?id=CVE-2015-7035
21 Oct 2015 — Apple Mac EFI before 2015-002, as used in OS X before 10.11.1 and other products, mishandles arguments, which allows attackers to reach "unused" functions via unspecified vectors. Apple Mac EFI en versiones anteriores a 2015-002, tal como se utiliza en OS X en versiones anteriores a 10.11.1 y otros productos, no maneja correctamente argumentos, lo que permite a atacantes llegar a las funciones 'unused' a través de vectores no especificados. OS X El Capitan 10.11.1 and Security Update 2015-007 are now availa... • http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html • CWE-17: DEPRECATED: Code •