|
270601
|
- |
|
apple
|
mac_os_x
|
The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-5854
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270602
|
- |
|
apple
|
mac_os_x
|
AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-5853
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270603
|
- |
|
apple
|
mac_os_x
|
The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers to bypass intended access restrictions by leverag…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5849
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270604
|
- |
|
apple
|
mac_os_x
|
Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.
|
CWE-200
Information Exposure
|
CVE-2015-5836
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270605
|
- |
|
apple
|
mac_os_x
|
The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access by visiting an unatt…
|
CWE-254
7PK - Security Features
|
CVE-2015-5833
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270606
|
- |
|
apple
|
mac_os_x
|
The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerabilit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5830
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270607
|
- |
|
opensuse apple
|
leap safari
|
The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass inten…
|
CWE-20
Improper Input Validation
|
CVE-2015-5828
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270608
|
- |
|
apple
|
safari
|
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-5780
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270609
|
- |
|
cybozu
|
garoon
|
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended l…
|
CWE-287
Improper Authentication
|
CVE-2015-5649
|
2024-11-21 11:33 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270610
|
- |
|
python
|
python
|
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE…
|
NVD-CWE-Other
|
CVE-2015-5652
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|