CVE-2015-5780
https://notcve.org/view.php?id=CVE-2015-5780
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors. La implementación de Safari Extensions en Apple Safari en versiones anteriores a 9, no requiere confirmación del usuario antes de reemplazar una extensión instalada, lo que tiene un impacto y vectores de ataque no especificados. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html http://www.securitytracker.com/id/1033688 https://support.apple.com/HT205265 • CWE-20: Improper Input Validation •
CVE-2015-5764
https://notcve.org/view.php?id=CVE-2015-5764
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767. Vulnerabilidad en la interfaz de usuario en Safari en Apple iOS en versiones anteriores a la 9, permite a atacantes remotos suplantar URLs a través de vectores no especificados, una vulnerabilidad diferente a CVE-2015-5765 y CVE-2015-5767. • http://intothesymmetry.blogspot.it/2015/09/apple-safari-uri-spoofing-cve-2015-5764.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html http://packetstormsecurity.com/files/133847/Apple-Safari-8.0.8-URI-Spoofing.html http://seclists.org/fulldisclosure/2015/Oct/16 http://www.securityfocus.com/bid/76764 http://www.securitytracker.com/id/1033609 https://support.apple.com/HT205212 https://sup • CWE-20: Improper Input Validation •
CVE-2015-5805
https://notcve.org/view.php?id=CVE-2015-5805
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. Vulnerabilidad en WebKit, tal como se utiliza en Apple iOS en versiones anteriores a 9 y iTunes en versiones anteriores a 12.3, permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de un sitio web manipulado, una vulnerabilidad diferente a otras CVEs WebKit listadas en APPLE-SA-2015-09-16-1 y APPLE-SA-2015-09-16-3. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html http://www.securityfocus.com/bid/76763 http://www.securitytracker.com/id/1033609 https://support.apple.com/HT205212 https://support.apple.com/HT205221 https://support.apple.com/HT205265 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-5792
https://notcve.org/view.php?id=CVE-2015-5792
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. Vulnerabilidad en WebKit, tal como se utiliza en Apple iOS en versiones anteriores a 9 y iTunes en versiones anteriores a 12.3, permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de un sitio web manipulado, una vulnerabilidad diferente a otras CVEs WebKit listadas en APPLE-SA-2015-09-16-1 y APPLE-SA-2015-09-16-3. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html http://www.securityfocus.com/bid/76763 http://www.securitytracker.com/id/1033609 https://support.apple.com/HT205212 https://support.apple.com/HT205221 https://support.apple.com/HT205265 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-5801
https://notcve.org/view.php?id=CVE-2015-5801
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. Vulnerabilidad en WebKit, tal como se utiliza en Apple iOS en versiones anteriores a 9 y iTunes en versiones anteriores a 12.3, permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de un sitio web manipulado, una vulnerabilidad diferente a otras CVEs WebKit listadas en APPLE-SA-2015-09-16-1 y APPLE-SA-2015-09-16-3. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html http://www.securityfocus.com/bid/76763 http://www.securitytracker.com/id/1033609 http://www.ubuntu.com/usn/USN-2937-1 https://support.apple.com/HT205212 https://support.apple.com/HT205221 https:/ • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •