Filtered by vendor Apple
Subscriptions
Filtered by product Mac Os X
Subscriptions
Total
5567 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2014-4460 | 1 Apple | 2 Iphone Os, Mac Os X | 2024-11-21 | N/A |
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files. | ||||
CVE-2014-4459 | 1 Apple | 5 Iphone Os, Itunes, Mac Os X and 2 more | 2024-11-21 | N/A |
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document. | ||||
CVE-2014-4458 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors. | ||||
CVE-2014-4453 | 1 Apple | 2 Iphone Os, Mac Os X | 2024-11-21 | N/A |
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors. | ||||
CVE-2014-4444 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, which allows local users to gain privileges in opportunistic circumstances by leveraging a Fast User Switching login. | ||||
CVE-2014-4443 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.1 data. | ||||
CVE-2014-4442 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
The kernel in Apple OS X before 10.10 allows local users to cause a denial of service (panic) via a message to a system control socket. | ||||
CVE-2014-4441 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attackers to read or write to files by leveraging a state in which File Sharing is permanently enabled. | ||||
CVE-2014-4440 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mobile-configuration profiles, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging access to an unintended proxy server. | ||||
CVE-2014-4439 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from a message, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading a message intended exclusively for other recipients. | ||||
CVE-2014-4438 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstation on which screen locking had been attempted. | ||||
CVE-2014-4437 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application that specifies a crafted handler for the Content-Type field of an object. | ||||
CVE-2014-4436 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application. | ||||
CVE-2014-4435 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN entry, which makes it easier for physically proximate attackers to obtain access via a brute-force attack involving a series of reboots. | ||||
CVE-2014-4434 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted filename on an HFS filesystem. | ||||
CVE-2014-4433 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arbitrary code via crafted resource forks in an HFS filesystem. | ||||
CVE-2014-4432 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a setting-update action and a reboot action, which might make it easier for physically proximate attackers to obtain cleartext data by leveraging ignorance of the reboot requirement. | ||||
CVE-2014-4431 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physically proximate attackers to view windows by leveraging an unattended workstation. | ||||
CVE-2014-4430 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, which makes it easier for physically proximate attackers to obtain cleartext data via a remount. | ||||
CVE-2014-4428 | 1 Apple | 1 Mac Os X | 2024-11-21 | N/A |
Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by leveraging previous pairing. |