Apple Security Advisories · July 2015 — Apple Security Advisories
73 advisories 73 CVEs

Apple-vendor CVEs for 2015-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-3704

macOSWeaponized exploitHIGH2015-07-01

runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2015-3704

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3673

macOSWeaponized exploitHIGH2015-07-01

Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.

CVEs:CVE-2015-3673

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3717

macOSWeaponized exploitCRITICAL2015-07-01

Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2015-3717

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3667

macOSWeaponized exploitCRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability tha...

CVEs:CVE-2015-3667

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3687

macOSWeaponized exploitCRITICAL2015-07-01

CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3...

CVEs:CVE-2015-3687

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3674

macOSWeaponized exploitCRITICAL2015-07-01

afpserver in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2015-3674

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3668

macOSWeaponized exploitCRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability tha...

CVEs:CVE-2015-3668

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3679

macOSWeaponized exploitCRITICAL2015-07-01

Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3680, CVE-2015-3681, and CVE-2015...

CVEs:CVE-2015-3679

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3680

macOSWeaponized exploitCRITICAL2015-07-01

Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3681, and CVE-2015...

CVEs:CVE-2015-3680

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3681

macOSWeaponized exploitCRITICAL2015-07-01

Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015...

CVEs:CVE-2015-3681

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3682

macOSWeaponized exploitCRITICAL2015-07-01

Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3680, and CVE-2015...

CVEs:CVE-2015-3682

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3691

macOSWeaponized exploitHIGH2015-07-01

The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages control of a function pointer.

CVEs:CVE-2015-3691

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3706

macOSWeaponized exploitHIGH2015-07-01

IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3705.

CVEs:CVE-2015-3706

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3708

macOSWeaponized exploitHIGH2015-07-01

kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a crafted app that conducts a symlink attack.

CVEs:CVE-2015-3708

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3714

macOSWeaponized exploitCRITICAL2015-07-01

Apple OS X before 10.10.4 does not properly consider custom resource rules during app signature verification, which allows attackers to bypass intended launch restrictions via a modified app.

CVEs:CVE-2015-3714

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3676

macOSWeaponized exploitMEDIUM2015-07-01

AppleGraphicsControl in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information via a crafted app.

CVEs:CVE-2015-3676

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3720

macOSWeaponized exploitMEDIUM2015-07-01

The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, which allows attackers to obtain sensitive memory-layout information via a crafted app.

CVEs:CVE-2015-3720

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3695

macOSWeaponized exploitHIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-...

CVEs:CVE-2015-3695

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3700

macOSWeaponized exploitHIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-...

CVEs:CVE-2015-3700

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3185

OtherPoC exploitMEDIUM2015-07-15

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote a...

CVEs:CVE-2015-3185

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
xcode affected apple — —
Upstream advisory

CVE-2015-0253

OtherPoC exploitHIGH2015-07-20

The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a...

CVEs:CVE-2015-0253

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2015-1819

OtherPoC exploitHIGH2015-07-21

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

CVEs:CVE-2015-1819

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2015-3693

macOSEPSS <= 49%HIGH2015-07-01

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause...

CVEs:CVE-2015-3693

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3703

macOSEPSS <= 49%CRITICAL2015-07-01

ImageIO in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image.

CVEs:CVE-2015-3703

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3684

macOSEPSS <= 49%CRITICAL2015-07-01

The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted credentials in a URL.

CVEs:CVE-2015-3684

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3686

macOSEPSS <= 49%CRITICAL2015-07-01

CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3687, CVE-2015-3...

CVEs:CVE-2015-3686

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3688

macOSEPSS <= 49%CRITICAL2015-07-01

CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3...

CVEs:CVE-2015-3688

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3661

macOSEPSS <= 49%CRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability tha...

CVEs:CVE-2015-3661

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3662

macOSEPSS <= 49%CRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability tha...

CVEs:CVE-2015-3662

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3663

macOSEPSS <= 49%CRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability tha...

CVEs:CVE-2015-3663

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3666

macOSEPSS <= 49%CRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability tha...

CVEs:CVE-2015-3666

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3685

macOSEPSS <= 49%CRITICAL2015-07-01

CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3686, CVE-2015-3687, CVE-2015-3...

CVEs:CVE-2015-3685

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3689

macOSEPSS <= 49%CRITICAL2015-07-01

CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3...

CVEs:CVE-2015-3689

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3694

macOSEPSS <= 49%CRITICAL2015-07-01

FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3719.

CVEs:CVE-2015-3694

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3719

macOSEPSS <= 49%CRITICAL2015-07-01

TrueTypeScaler in FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3694.

CVEs:CVE-2015-3719

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3712

macOSEPSS <= 49%HIGH2015-07-01

The NVIDIA graphics driver in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds write) via a crafted app.

CVEs:CVE-2015-3712

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3723

iOSEPSS <= 49%CRITICAL2015-07-01

CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724.

CVEs:CVE-2015-3723

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2015-3713

macOSEPSS <= 49%CRITICAL2015-07-01

QuickTime in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted movie file.

CVEs:CVE-2015-3713

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3664

OtherEPSS <= 49%CRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3665 and CVE-2015-3669.

CVEs:CVE-2015-3664

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple — —
Upstream advisory

CVE-2015-3665

OtherEPSS <= 49%CRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3669.

CVEs:CVE-2015-3665

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple — —
Upstream advisory

CVE-2015-3669

OtherEPSS <= 49%CRITICAL2015-07-01

QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3665.

CVEs:CVE-2015-3669

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2015-3707

macOSEPSS <= 49%HIGH2015-07-01

The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

CVEs:CVE-2015-3707

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3683

macOSEPSS <= 49%HIGH2015-07-01

The Bluetooth HCI interface implementation in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVEs:CVE-2015-3683

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3659

iOSEPSS <= 49%CRITICAL2015-07-01

The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remo...

CVEs:CVE-2015-3659

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
safari affected apple — —
Upstream advisory

CVE-2015-3705

macOSEPSS <= 49%HIGH2015-07-01

IOAcceleratorFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-3706.

CVEs:CVE-2015-3705

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3724

iOSEPSS <= 49%CRITICAL2015-07-01

CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723.

CVEs:CVE-2015-3724

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2015-3718

macOSEPSS <= 49%CRITICAL2015-07-01

systemstatsd in the System Stats subsystem in Apple OS X before 10.10.4 does not properly interpret data types encountered in interprocess communication, which allows attackers to execute arbitrary code with systemstatsd privileges via a crafted app, r...

CVEs:CVE-2015-3718

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3675

macOSEPSS <= 49%MEDIUM2015-07-01

The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attackers to bypass HTTP authentication via a crafted URL.

CVEs:CVE-2015-3675

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3658

iOSEPSS <= 49%MEDIUM2015-07-01

The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, whi...

CVEs:CVE-2015-3658

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
safari affected apple — —
Upstream advisory

CVE-2015-3727

iOSEPSS <= 49%MEDIUM2015-07-01

WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web sit...

CVEs:CVE-2015-3727

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
safari affected apple — —
Upstream advisory

CVE-2015-3710

macOSEPSS <= 49%MEDIUM2015-07-01

Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh operation, and consequently cause a visit to an arbitrary web site, via a crafted HTML e-mail message.

CVEs:CVE-2015-3710

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3660

SafariEPSS <= 49%CRITICAL2015-07-01

Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.

CVEs:CVE-2015-3660

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2015-3722

iOSEPSS <= 49%HIGH2015-07-01

Application Store in Apple iOS before 8.4 does not ensure the uniqueness of bundle IDs, which allows attackers to cause a denial of service (ID collision and launch outage) via a crafted universal provisioning profile app.

CVEs:CVE-2015-3722

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2015-3725

iOSEPSS <= 49%HIGH2015-07-01

MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.

CVEs:CVE-2015-3725

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2015-3715

macOSEPSS <= 49%MEDIUM2015-07-01

The code-signing implementation in Apple OS X before 10.10.4 does not properly consider libraries that are external to an application bundle, which allows attackers to bypass intended launch restrictions via a crafted library.

CVEs:CVE-2015-3715

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3690

macOSEPSS <= 49%MEDIUM2015-07-01

The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.

CVEs:CVE-2015-3690

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3721

macOSEPSS <= 49%MEDIUM2015-07-01

The kernel in Apple iOS before 8.4 and OS X before 10.10.4 does not properly handle HFS parameters, which allows attackers to obtain sensitive memory-layout information via a crafted app.

CVEs:CVE-2015-3721

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3677

macOSEPSS <= 49%MEDIUM2015-07-01

The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.

CVEs:CVE-2015-3677

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3711

macOSEPSS <= 49%MEDIUM2015-07-01

The NTFS implementation in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.

CVEs:CVE-2015-3711

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3696

macOSEPSS <= 49%HIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-...

CVEs:CVE-2015-3696

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3697

macOSEPSS <= 49%HIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-...

CVEs:CVE-2015-3697

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3698

macOSEPSS <= 49%HIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3699, CVE-2015-3700, CVE-2015-...

CVEs:CVE-2015-3698

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3699

macOSEPSS <= 49%HIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3700, CVE-2015-...

CVEs:CVE-2015-3699

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3701

macOSEPSS <= 49%HIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-...

CVEs:CVE-2015-3701

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3728

iOSEPSS <= 49%MEDIUM2015-07-01

The WiFi Connectivity feature in Apple iOS before 8.4 allows remote Wi-Fi access points to trigger an automatic association, with an arbitrary security type, by operating with a recognized ESSID within an 802.11 network's coverage area.

CVEs:CVE-2015-3728

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2015-3716

macOSEPSS <= 49%CRITICAL2015-07-01

Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.

CVEs:CVE-2015-3716

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3678

macOSEPSS <= 49%HIGH2015-07-01

AppleThunderboltEDMService in Apple OS X before 10.10.4 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified Thunderbolt commands.

CVEs:CVE-2015-3678

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3702

macOSEPSS <= 49%HIGH2015-07-01

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-...

CVEs:CVE-2015-3702

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3726

iOSEPSS <= 49%CRITICAL2015-07-01

The Telephony subsystem in Apple iOS before 8.4 allows physically proximate attackers to execute arbitrary code via a crafted (1) SIM or (2) UIM card.

CVEs:CVE-2015-3726

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2015-3672

macOSEPSS <= 49%HIGH2015-07-01

Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which allows local users to obtain admin privileges via unspecified vectors.

CVEs:CVE-2015-3672

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3671

macOSEPSS <= 49%HIGH2015-07-01

Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

CVEs:CVE-2015-3671

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3692

macOSEPSS <= 49%HIGH2015-07-01

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging root privileges.

CVEs:CVE-2015-3692

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2015-3709

macOSEPSS <= 49%MEDIUM2015-07-01

Race condition in kext tools in Apple OS X before 10.10.4 allows local users to bypass intended signature requirements for kernel extensions by leveraging improper pathname validation.

CVEs:CVE-2015-3709

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.