
CVE-2015-5894 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5894
01 Oct 2015 — The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate. La implementación del certificado de confianza X.509 en Apple OS X en versiones anteriores a 10.11 no reconoce que el indicador kSecRevocationRequirePositiveResponse implica un requerimiento de control de rev... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-17: DEPRECATED: Code •

CVE-2015-5897 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5897
01 Oct 2015 — The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using an environment variable to inject code into processes that rely on this framework. El framework Address Book en Apple OS X en versiones anteriores a 10.11 permite a usuarios locales obtener privilegios utilizando una variable de entorno para inyectar código en procesos que dependen de este framework. OS X El Capitan 10.11 is now available and addresses close to 100 vulnerabilities that may exist in prior rel... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-5900 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5900
01 Oct 2015 — The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended address. El registro de rango protegido en el componente EFI en Apple OS X en versiones anteriores a 10.11 tiene un valor incorrecto, lo que permite a atacantes causar una denegación de servicio (fallo de arranque) a través de una aplicación manipulada que escribe a una dirección no intencionada.... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-254: 7PK - Security Features •

CVE-2015-5901 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5901
01 Oct 2015 — The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive. La funcionalidad Secure Empty Trash en Apple OS X en versiones anteriores a 10.11 no borra adecuadamente los archivos Trash, lo que podría permitir a usuarios locales obtener información sensible medainte la lectura del almacenamiento multimedia, según lo demostrado mediante la lec... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-5902 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5902
01 Oct 2015 — The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors. La funcionalidad de depuración en el kernel en Apple OS X en versiones anteriores a 10.11 no gestiona correctamente el estado, lo que permite a usuarios locales provocar una denegación de servicio a través de vectores no especificados. OS X El Capitan 10.11 is now available and addresses close to 100 vulnerabilities that may exist in prior releases. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html •

CVE-2015-5913 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5913
01 Oct 2015 — Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request. Heimdal, tal como se utiliza en Apple OS X en versiones anteriores a 10.11, permite a atacantes remotos llevar a cabo ataques de repetición contra el servidor SMB a través de datos en un paquete que representan una petición de autenticación Kerberos. OS X El Capitan 10.11 is now available and addresses close to 100 vulnerabili... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-284: Improper Access Control •

CVE-2015-5914 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5914
01 Oct 2015 — The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498. El componente EFI en Apple OS X en versiones anteriores a 10.11 permite a atacantes físicamente próximos modificar el firmware durante el proceso de actualización de EFI insertando un adaptado... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-17: DEPRECATED: Code •

CVE-2015-5915 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5915
01 Oct 2015 — Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified impact and attack vectors. Apple OS X en versiones anteriores a 10.11 no asegura que el estado de bloqueo del llavero se muestre correctamente, lo que tiene un impacto y vectores de ataque no especificados. OS X El Capitan 10.11 is now available and addresses close to 100 vulnerabilities that may exist in prior releases. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-17: DEPRECATED: Code •

CVE-2015-5917 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5917
01 Oct 2015 — The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring. La implementación de glob en tnftpd (anteriormente lukemftpd), tal como se utiliza en Apple OS X en versiones anteriores a 10.11 permite a atacantes remotos provocar una denegación de servicio (corrupción de me... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2015-5922 – Apple Security Advisory 2015-09-30-03
https://notcve.org/view.php?id=CVE-2015-5922
01 Oct 2015 — Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors. Vulnerabilidad no especificada en International Components para Unicode (ICU) en versiones anteriores a 53.1.0, tal como se utiliza en Apple OS X en versiones anteriores a 10.11 y watchOS en versiones anteriores a 2, tiene un impacto y vectores de ataque desconocidos. OS X El Capitan 10.11 is now available and addresses close t... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html •