CVE-2015-5828
https://notcve.org/view.php?id=CVE-2015-5828
09 Oct 2015 — The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site. La API en el componente WebKit Plug-ins en Apple Safari en versiones anteriores a 9 no proporciona notificación de un un código de estado HTTP Redirection (también conocida como 3xx) a un plugin, lo que permite a atacantes remotos eludir las restricciones destinad... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html • CWE-20: Improper Input Validation •
CVE-2015-5780
https://notcve.org/view.php?id=CVE-2015-5780
01 Oct 2015 — The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors. La implementación de Safari Extensions en Apple Safari en versiones anteriores a 9, no requiere confirmación del usuario antes de reemplazar una extensión instalada, lo que tiene un impacto y vectores de ataque no especificados. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html • CWE-20: Improper Input Validation •
CVE-2015-5820
https://notcve.org/view.php?id=CVE-2015-5820
18 Sep 2015 — WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) tel://, (2) facetime://, or (3) facetime-audio:// URL. Vulnerabilidad en WebKit en Apple iOS en versiones anteriores a 9, permite a atacantes desencadenar una acción de marcado a través de la URL (1) tel://, (2) facetime:// o (3) facetime-audio:// manipulada. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html • CWE-20: Improper Input Validation •
CVE-2015-3801
https://notcve.org/view.php?id=CVE-2015-3801
18 Sep 2015 — The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors. Vulnerabilidad en la implementación de la API document.cookie en el subsistema CFNetwork Cookies en WebKit en Apple iOS en versiones anteriores a la 9, permite a atacantes remotos eludir una restricción destinada a una única cookie a través de vectores no especificados. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2015-5764
https://notcve.org/view.php?id=CVE-2015-5764
18 Sep 2015 — The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767. Vulnerabilidad en la interfaz de usuario en Safari en Apple iOS en versiones anteriores a la 9, permite a atacantes remotos suplantar URLs a través de vectores no especificados, una vulnerabilidad diferente a CVE-2015-5765 y CVE-2015-5767. • http://intothesymmetry.blogspot.it/2015/09/apple-safari-uri-spoofing-cve-2015-5764.html • CWE-20: Improper Input Validation •
CVE-2015-5765
https://notcve.org/view.php?id=CVE-2015-5765
18 Sep 2015 — The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767. Vulnerabilidad en la interfaz de usuario en Safari en Apple iOS en versiones anteriores a la 9, permite a atacantes remotos suplantar URLs a través de vectores no especificados, una vulnerabilidad diferente a CVE-2015-5764 y CVE-2015-5767. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html • CWE-20: Improper Input Validation •
CVE-2015-5767
https://notcve.org/view.php?id=CVE-2015-5767
18 Sep 2015 — The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765. Vulnerabilidad en la interfaz de usuario en Safari en Apple iOS en versiones anteriores a la 9, permite a atacantes remotos suplantar URLs a través de vectores no especificados, una vulnerabilidad diferente a CVE-2015-5764 y CVE-2015-5765. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html • CWE-20: Improper Input Validation •
CVE-2015-5788
https://notcve.org/view.php?id=CVE-2015-5788
18 Sep 2015 — The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element. Vulnerabilidad en la implementación WebKit Canvas en Apple iOS en versiones anteriores a la 9, permite a atacantes remotos eludir la Same Origin Policy y obtener información de imagen sensible a través de vectores que implican un elemento CANVAS. • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2015-5789
https://notcve.org/view.php?id=CVE-2015-5789
18 Sep 2015 — WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. Vulnerabilidad en WebKit, tal como se utiliza en Apple iOS en versiones anteriores a 9 y iTunes en versiones anteriores a 12.3, permite a atacantes remotos ejecutar código arbitrario o causar una d... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-5790
https://notcve.org/view.php?id=CVE-2015-5790
18 Sep 2015 — WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. Vulnerabilidad en WebKit, tal como se utiliza en Apple iOS en versiones anteriores a 9 y iTunes en versiones anteriores a 12.3, permite a atacantes remotos ejecutar código arbitrario o causar una d... • http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •