Apple Security Advisories · March 2015 — Apple Security Advisories
31 advisories 31 CVEs

Apple-vendor CVEs for 2015-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-1067

tvOSPoC exploitMEDIUM2015-03-10

Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via cra...

CVEs:CVE-2015-1067

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2015-0228

OtherPoC exploitHIGH2015-03-08

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has ...

CVEs:CVE-2015-0228

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2015-2301

OtherPoC exploitCRITICAL2015-03-23

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an att...

CVEs:CVE-2015-2301

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-2787

OtherPoC exploitCRITICAL2015-03-30

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that...

CVEs:CVE-2015-2787

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-3416

OtherPoC exploitCRITICAL2015-03-19

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-bas...

CVEs:CVE-2015-3416

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2015-3415

OtherPoC exploitCRITICAL2015-03-19

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via...

CVEs:CVE-2015-3415

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2015-1061

tvOSPoC exploitHIGH2015-03-10

IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.

CVEs:CVE-2015-1061

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2015-1066

macOSPoC exploitHIGH2015-03-10

Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2015-1066

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-1063

iOSPoC exploitHIGH2015-03-10

CoreTelephony in Apple iOS before 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a Class 0 SMS message.

CVEs:CVE-2015-1063

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2015-1062

tvOSPoC exploitMEDIUM2015-03-10

MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app.

CVEs:CVE-2015-1062

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2015-1065

macOSPoC exploitCRITICAL2015-03-10

Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.

CVEs:CVE-2015-1065

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2015-1064

iOSPoC exploitHIGH2015-03-10

Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended activation requirement and read the home screen by leveraging an application crash during the activation process.

CVEs:CVE-2015-1064

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2015-2348

OtherEPSS <= 49%MEDIUM2015-03-30

The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extensio...

CVEs:CVE-2015-2348

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-3414

OtherEPSS <= 49%CRITICAL2015-03-19

SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impa...

CVEs:CVE-2015-3414

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2015-1071

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1071

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1076

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1076

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1081

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1081

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1083

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1083

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1069

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1069

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1068

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1068

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1070

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1070

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1072

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1072

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1073

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1073

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1074

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1074

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1077

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1077

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1078

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1078

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1079

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1079

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1080

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1080

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1082

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1082

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-1075

SafariEPSS <= 49%CRITICAL2015-03-18

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabi...

CVEs:CVE-2015-1075

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
safari affected apple
Upstream advisory

CVE-2015-1084

SafariEPSS <= 49%MEDIUM2015-03-18

The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.

CVEs:CVE-2015-1084

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.