CVE-2015-1067 – Apple Security Advisory 2015-03-09-2
https://notcve.org/view.php?id=CVE-2015-1067
10 Mar 2015 — Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204 and CVE-2015-1637. Secure Transport en Apple iOS anterior a 8.2, Apple OS X hasta 10.10.2, y Apple TV anterior a 7.1 no restringe correctamente las transiciones de est... • http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html • CWE-310: Cryptographic Issues •
CVE-2015-1062 – Apple Security Advisory 2015-03-09-2
https://notcve.org/view.php?id=CVE-2015-1062
10 Mar 2015 — MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app. MobileStorageMounter en Apple iOS anterior a 8.2 y Apple TV anterior a 7.1 no elimina las carpetas de imágenes de discos inválidas, lo que permite a atacantes remotos crear carpetas en localizaciones del sistema de ficheros arbitrarias a través de una aplicación manipulada. iOS 8.2 is now available and a... • http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.html • CWE-19: Data Processing Errors •
CVE-2015-1061 – Apple Security Advisory 2015-03-09-2
https://notcve.org/view.php?id=CVE-2015-1061
10 Mar 2015 — IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling. IOSurface en Apple iOS anterior a 8.2, Apple OS X hasta 10.10.2, y Apple TV anterior a 7.1 permite a atacantes ejecutar código arbitrario en un contexto privilegiado a través de una aplicación manipulada que aprovecha la 'confusión de tipos' durante el manejo de objetos se... • http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2014-4476 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4476
28 Jan 2015 — WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4477 and CVE-2014-4479. WebKit, utilizado en Apple iOS anterior a 8.1.3; Apple Safari anterior a 6.2.3, 7.x anterior a 7.1.3, y 8.x anterior a 8.0.3; y Apple TV anterior a 7.0.3, permite a a... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-4491 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4491
28 Jan 2015 — The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addresses within an OSBundleMachOHeaders key in a response, which makes it easier for attackers to bypass the ASLR protection mechanism via a crafted app. Las APIs de extensiónTen el kernel en Apple iOS anterior a 8.1.3, Apple OS X anterior a 10.10.2, y Apple TV anterior a 7.0.3 no previene la presencia de direcciones dentro de una clave OSBundleMachOHeaders en una ... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-4489 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4489
28 Jan 2015 — IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly initialize event queues, which allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app. IOHIDFamily en Apple iOS anterior a 8.1.3, Apple OS X anterior a 10.10.2, y Apple TV anterior a 7.0.3 no inicializa correctamente las colas de eventos, lo que permite a atacantes ejecutar código arbitrario o causar una denegación... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html •
CVE-2014-4480 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4480
28 Jan 2015 — Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink. Salto de directorio en afc en AppleFileConduit en Apple iOS anterior a 8.1.3 y Apple TV anterior a 7.0.permite a atacantes remotos acceder a localizaciones del sistema de ficheros mediante la creación de un enlace simbólico. Apple TV 7.0.3 is now available and addresses arbitrary code execution, access bypass, unsig... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2014-4496 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4496
28 Jan 2015 — The mach_port_kobject interface in the kernel in Apple iOS before 8.1.3 and Apple TV before 7.0.3 does not properly restrict kernel-address and heap-permutation information, which makes it easier for attackers to bypass the ASLR protection mechanism via a crafted app. La interfaz mach_port_kobject en el kernel en Apple iOS anterior a 8.1.3 y Apple TV anterior a 7.0.3 no restringe correctamente la información de la dirección del kernel y la permutación de la memoria dinámica, lo que facilita a atacantes evad... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-4487 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4487
28 Jan 2015 — Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows attackers to execute arbitrary code in a privileged context via a crafted app. Desbordamiento de buffer en IOHIDFamily en Apple iOS anterior a 8.1.3, Apple OS X anterior a 10.10.2, y Apple TV anterior a 7.0.3 permite a atacantes ejecutar código arbitrario en un contexto privilegiado a través de una aplicación manipulada. OS X 10.10.2 and Security Update 2015-001 are now available and address... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-4481 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4481
28 Jan 2015 — Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document. Desbordamiento de enteros en CoreGraphics en Apple iOS anterior a 8.1.3, Apple OS X anterior a 10.10.2, y Apple TV anterior a 7.0.3 pemite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (caída de aplicación) a través de un documento PDF... • https://github.com/feliam/CVE-2014-4481 • CWE-189: Numeric Errors •