Apple Security Advisories · December 2015 — Apple Security Advisories
71 advisories 71 CVEs

Apple-vendor CVEs for 2015-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-7112

watchOSWeaponized exploitHIGH2015-12-09

The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different...

CVEs:CVE-2015-7112

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7068

watchOSWeaponized exploitHIGH2015-12-09

IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unsp...

CVEs:CVE-2015-7068

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7077

macOSWeaponized exploitHIGH2015-12-09

The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access) via unspecified vectors.

CVEs:CVE-2015-7077

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7078

macOSWeaponized exploitHIGH2015-12-09

Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vectors involving VM objects.

CVEs:CVE-2015-7078

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7108

macOSWeaponized exploitHIGH2015-12-09

The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2015-7108

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7106

macOSWeaponized exploitHIGH2015-12-09

The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2015-7106

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7047

watchOSWeaponized exploitHIGH2015-12-09

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted mach message that is misparsed.

CVEs:CVE-2015-7047

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7084

watchOSWeaponized exploitHIGH2015-12-09

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.

CVEs:CVE-2015-7084

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7110

tvOSWeaponized exploitHIGH2015-12-09

The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image.

CVEs:CVE-2015-7110

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2015-7083

watchOSWeaponized exploitHIGH2015-12-09

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7084.

CVEs:CVE-2015-7083

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-3195

OtherPoC exploitHIGH2015-12-03

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obta...

CVEs:CVE-2015-3195

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-8472

OtherPoC exploitCRITICAL2015-12-03

Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or po...

CVEs:CVE-2015-8472

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7039

watchOSEPSS <= 49%CRITICAL2015-12-09

Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7038.

CVEs:CVE-2015-7039

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7038

watchOSEPSS <= 49%CRITICAL2015-12-09

Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7039.

CVEs:CVE-2015-7038

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7053

watchOSEPSS <= 49%CRITICAL2015-12-09

ImageIO in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image.

CVEs:CVE-2015-7053

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7073

watchOSEPSS <= 49%CRITICAL2015-12-09

Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted SSL handshake.

CVEs:CVE-2015-7073

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7075

watchOSEPSS <= 49%CRITICAL2015-12-09

CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.

CVEs:CVE-2015-7075

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7105

watchOSEPSS <= 49%CRITICAL2015-12-09

CoreGraphics in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.

CVEs:CVE-2015-7105

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7074

tvOSEPSS <= 49%CRITICAL2015-12-09

CoreMedia Playback in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed media file.

CVEs:CVE-2015-7074

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2015-7111

watchOSEPSS <= 49%HIGH2015-12-09

The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different...

CVEs:CVE-2015-7111

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7107

macOSEPSS <= 49%CRITICAL2015-12-09

QuickLook in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file.

CVEs:CVE-2015-7107

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2015-7072

watchOSEPSS <= 49%HIGH2015-12-09

dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2015-7072

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7113

watchOSEPSS <= 49%HIGH2015-12-09

The LaunchServices component in Apple iOS before 9.2 and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a malformed plist.

CVEs:CVE-2015-7113

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2015-7054

watchOSEPSS <= 49%CRITICAL2015-12-09

zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not initialize memory for an unspecified data structure, which allows remote attackers to execute arbitrary code via a crafted ...

CVEs:CVE-2015-7054

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7048

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7048

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7095

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7095

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7096

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7096

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7097

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7097

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7098

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7098

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7099

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7099

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7100

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7100

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7102

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7102

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7103

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7103

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7064

watchOSEPSS <= 49%CRITICAL2015-12-09

OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2...

CVEs:CVE-2015-7064

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7066

watchOSEPSS <= 49%CRITICAL2015-12-09

OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2...

CVEs:CVE-2015-7066

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7101

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE...

CVEs:CVE-2015-7101

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7079

tvOSEPSS <= 49%HIGH2015-12-09

dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2015-7079

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2015-7051

tvOSEPSS <= 49%HIGH2015-12-09

MobileStorageMounter in Apple iOS before 9.2 and tvOS before 9.1 mishandles the timing of trust-cache loading, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2015-7051

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2015-7104

tvOSEPSS <= 49%CRITICAL2015-12-09

WebKit in Apple Safari before 9.0.2 and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVEs:CVE-2015-7104

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
tvos affected apple
Upstream advisory

CVE-2015-7109

tvOSEPSS <= 49%HIGH2015-12-09

IOAcceleratorFamily in Apple OS X before 10.11.2 and tvOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVEs:CVE-2015-7109

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2015-7069

iOSEPSS <= 49%HIGH2015-12-09

Mobile Replayer in GPUTools Framework in Apple iOS before 9.2 allows attackers to execute arbitrary code in a privileged context via an app that provides a crafted pathname, a different vulnerability than CVE-2015-7070.

CVEs:CVE-2015-7069

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2015-7070

iOSEPSS <= 49%HIGH2015-12-09

Mobile Replayer in GPUTools Framework in Apple iOS before 9.2 allows attackers to execute arbitrary code in a privileged context via an app that provides a crafted pathname, a different vulnerability than CVE-2015-7069.

CVEs:CVE-2015-7070

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2015-7044

macOSEPSS <= 49%HIGH2015-12-09

The System Integrity Protection feature in Apple OS X before 10.11.2 mishandles union mounts, which allows attackers to execute arbitrary code in a privileged context via a crafted app with root privileges.

CVEs:CVE-2015-7044

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7055

tvOSEPSS <= 49%HIGH2015-12-09

AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2015-7055

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2015-7065

tvOSEPSS <= 49%CRITICAL2015-12-09

OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVEs:CVE-2015-7065

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2015-7059

watchOSEPSS <= 49%CRITICAL2015-12-09

The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-201...

CVEs:CVE-2015-7059

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7060

watchOSEPSS <= 49%CRITICAL2015-12-09

The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-201...

CVEs:CVE-2015-7060

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7061

watchOSEPSS <= 49%CRITICAL2015-12-09

The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-201...

CVEs:CVE-2015-7061

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7081

macOSEPSS <= 49%HIGH2015-12-09

iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVEs:CVE-2015-7081

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2015-7040

watchOSEPSS <= 49%HIGH2015-12-09

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7041, CVE-2015-7042, and CVE-2015-7043.

CVEs:CVE-2015-7040

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7041

watchOSEPSS <= 49%HIGH2015-12-09

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7042, and CVE-2015-7043.

CVEs:CVE-2015-7041

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7042

watchOSEPSS <= 49%HIGH2015-12-09

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7043.

CVEs:CVE-2015-7042

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7043

watchOSEPSS <= 49%HIGH2015-12-09

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7042.

CVEs:CVE-2015-7043

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7037

iOSEPSS <= 49%HIGH2015-12-09

Directory traversal vulnerability in Mobile Backup in Photos in Apple iOS before 9.2 allows attackers to read arbitrary files via a crafted pathname.

CVEs:CVE-2015-7037

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2015-7001

watchOSEPSS <= 49%MEDIUM2015-12-09

AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mishandles hard links, which allows attackers to bypass Contacts access revocation via a crafted app.

CVEs:CVE-2015-7001

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7071

macOSEPSS <= 49%HIGH2015-12-09

The File Bookmark component in Apple OS X before 10.11.2 allows attackers to bypass a sandbox protection mechanism for app scoped bookmarks via a crafted pathname.

CVEs:CVE-2015-7071

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7046

watchOSEPSS <= 49%LOW2015-12-09

The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ASLR protection mechanism via a crafted app with roo...

CVEs:CVE-2015-7046

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2015-7050

iOSEPSS <= 49%MEDIUM2015-12-09

WebKit in Apple iOS before 9.2 and Safari before 9.0.2 misparses content extensions, which allows remote attackers to obtain sensitive browsing-history information via a crafted web site.

CVEs:CVE-2015-7050

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2015-7058

tvOSEPSS <= 49%MEDIUM2015-12-09

Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 improperly validate keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.

CVEs:CVE-2015-7058

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2015-7045

tvOSEPSS <= 49%MEDIUM2015-12-09

Keychain Access in Apple OS X before 10.11.2 and tvOS before 9.1 improperly interacts with Keychain Agent, which allows attackers to spoof the Keychain Server via unspecified vectors.

CVEs:CVE-2015-7045

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2015-7093

iOSEPSS <= 49%MEDIUM2015-12-09

Safari in Apple iOS before 9.2 allows remote attackers to spoof a URL in the user interface via a crafted web site.

CVEs:CVE-2015-7093

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2015-7056

XcodeEPSS <= 49%HIGH2015-12-11

IDE SCM in Apple Xcode before 7.2 does not recognize .gitignore files, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging the presence of a file matching an ignore pattern.

CVEs:CVE-2015-7056

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2015-7094

macOSEPSS <= 49%LOW2015-12-09

CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL.

CVEs:CVE-2015-7094

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2015-7080

iOSEPSS <= 49%LOW2015-12-08

Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.

CVEs:CVE-2015-7080

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2015-7076

macOSEPSS <= 49%HIGH2015-12-09

The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

CVEs:CVE-2015-7076

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7052

macOSEPSS <= 49%HIGH2015-12-09

kext tools in Apple OS X before 10.11.2 mishandles kernel-extension loading, which allows local users to gain privileges via unspecified vectors.

CVEs:CVE-2015-7052

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7063

macOSEPSS <= 49%HIGH2015-12-09

The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a crafted pathname.

CVEs:CVE-2015-7063

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7067

macOSEPSS <= 49%MEDIUM2015-12-09

IOThunderboltFamily in Apple OS X before 10.11.2 allows local users to cause a denial of service (NULL pointer dereference) via an unspecified userclient type.

CVEs:CVE-2015-7067

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2015-7062

tvOSEPSS <= 49%MEDIUM2015-12-09

Apple OS X before 10.11.2 and tvOS before 9.1 allow local users to bypass intended configuration-profile installation restrictions via unspecified vectors.

CVEs:CVE-2015-7062

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2015-7049

XcodeEPSS <= 49%HIGH2015-12-11

otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different vulnerability than CVE-2015-7057.

CVEs:CVE-2015-7049

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2015-7057

XcodeEPSS <= 49%HIGH2015-12-11

otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different vulnerability than CVE-2015-7049.

CVEs:CVE-2015-7057

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.