
CVE-2014-4481 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4481
28 Jan 2015 — Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document. Desbordamiento de enteros en CoreGraphics en Apple iOS anterior a 8.1.3, Apple OS X anterior a 10.10.2, y Apple TV anterior a 7.0.3 pemite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (caída de aplicación) a través de un documento PDF... • https://github.com/feliam/CVE-2014-4481 • CWE-189: Numeric Errors •

CVE-2014-8821 – Apple Security Advisory 2015-01-27-4
https://notcve.org/view.php?id=CVE-2014-8821
28 Jan 2015 — The Intel Graphics Driver in Apple OS X before 10.10.2 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2014-8819 and CVE-2014-8820. Intel Graphics Driver en Apple OS X anterior a 10.10.2 permite a usuarios locales ganar privilegios a través de vectores no especificados, una vulnerabilidad diferente a CVE-2014-8819 y CVE-2014-8820. OS X 10.10.2 and Security Update 2015-001 are now available and address information disclosure, arbitrary code execution, cache c... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html •

CVE-2014-8820 – Apple Security Advisory 2015-01-27-4
https://notcve.org/view.php?id=CVE-2014-8820
28 Jan 2015 — The Intel Graphics Driver in Apple OS X before 10.10.2 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2014-8819 and CVE-2014-8821. Intel Graphics Driver en Apple OS X anterior a 10.10.2 permite a usuarios locales ganar privilegios a través de vectores no especificados, una vulnerabilidad diferente a CVE-2014-8819 y CVE-2014-8821. OS X 10.10.2 and Security Update 2015-001 are now available and address information disclosure, arbitrary code execution, cache c... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html •

CVE-2014-4495 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4495
28 Jan 2015 — The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restrictions via a crafted app. El kernel en Apple iOS anterior a 8.1.3, Apple OS X anterior a 10.10.2, y Apple TV anterior a 7.0.3 no fuerza el atributo de sólo lectura de un segmento de memoria compartida durante el uso de un modo de caché 'custom', lo que permite a ... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-8830 – Apple Security Advisory 2015-04-08-2
https://notcve.org/view.php?id=CVE-2014-8830
28 Jan 2015 — Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted accessor element in a Collada file. Desbordamiento de buffer basado en memoria dinámica en SceneKit en Apple OS X anterior a 10.10.2 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (caída de aplicación) a través de un elemento de acceso manipulado en un fichero Collada. OS X 10.10.2 and ... • http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-8837 – Apple Security Advisory 2015-01-27-4
https://notcve.org/view.php?id=CVE-2014-8837
28 Jan 2015 — Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arbitrary code in a privileged context via a crafted app. Múltiples vulnerabilidades no especificadas en el controlador Bluetooth en Apple OS X anterior a 10.10.2 permiten a atacantes ejecutar código arbitrario en un contexto privilegiado a través de una aplicación manipulada. OS X 10.10.2 and Security Update 2015-001 are now available and address information disclosure, arbitrary code execut... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html •

CVE-2014-4486 – Apple Security Advisory 2015-01-27-2
https://notcve.org/view.php?id=CVE-2014-4486
28 Jan 2015 — IOAcceleratorFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly handle resource lists and IOService userclient types, which allows attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via a crafted app. IOAcceleratorFamily en Apple iOS anterior a 8.1.3, Apple OS X anterior a 10.10.2, y Apple TV anterior a 7.0.3 no maneja correctamente las listas de recursos y los tipos de cliente usuario de IOService, lo que permite... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html •

CVE-2014-8827 – Apple Security Advisory 2015-01-27-4
https://notcve.org/view.php?id=CVE-2014-8827
28 Jan 2015 — LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically proximate attackers to obtain sensitive information by reading the screen. LoginWindow en Apple OS X anterior a 10.10.2 no pasa al estado de bloqueo de pantalla inmediatamente cuando se reactiva el ordenador después de un descanso, lo que permite a atacantes físicamente próximos obtener información sensible mediante la lectura de la pantalla. OS X 10.10.2 and... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html • CWE-284: Improper Access Control •

CVE-2014-8825 – Apple Security Advisory 2015-01-27-4
https://notcve.org/view.php?id=CVE-2014-8825
28 Jan 2015 — The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows local users to gain privileges or spoof directory-service responses via unspecified vectors. El kernel en Apple OS X anterior a 10.10.2 no realiza correctamente la validación identitysvc de cierta funcionalidad de los servicios del directorio, lo que permite a usuarios locales ganar privilegios o falsificar respuestas de los servicios del directorio a través de ve... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html • CWE-20: Improper Input Validation •

CVE-2014-4499 – Apple Security Advisory 2015-01-27-4
https://notcve.org/view.php?id=CVE-2014-4499
28 Jan 2015 — The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file. El proceso App Store en CommerceKit Framework en Apple OS X anterior a 10.10.2 coloca las credenciales de identificación de Apple en los registros de App Store, lo que permite a usuarios locales obtener información sensible mediante la lectura de un fichero. OS X 10.10.2 and Security Update 2015-001 are now avai... • http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •