|
273051
|
- |
|
apple
|
watchos iphone_os
|
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.
|
CWE-200
Information Exposure
|
CVE-2015-5916
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273052
|
- |
|
apple
|
mac_os_x iphone_os
|
The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
|
CWE-17
Code
|
CVE-2015-5912
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273053
|
- |
|
apple
|
mac_os_x_server
|
Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.
|
NVD-CWE-noinfo
|
CVE-2015-5911
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273054
|
- |
|
apple
|
xcode
|
IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network.
|
CWE-200
Information Exposure
|
CVE-2015-5910
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273055
|
- |
|
apple
|
xcode
|
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunist…
|
CWE-200
Information Exposure
|
CVE-2015-5909
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273056
|
- |
|
apple
|
iphone_os
|
WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.
|
CWE-310
Cryptographic Issues
|
CVE-2015-5907
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273057
|
- |
|
apple
|
iphone_os
|
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a pass…
|
CWE-200
Information Exposure
|
CVE-2015-5906
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273058
|
- |
|
apple
|
iphone_os
|
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.
|
CWE-254
7PK - Security Features
|
CVE-2015-5905
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273059
|
- |
|
apple
|
iphone_os
|
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.
|
CWE-254
7PK - Security Features
|
CVE-2015-5904
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273060
|
- |
|
apple
|
mac_os_x iphone_os watchos
|
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5903
|
2024-11-21 11:34 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|