Vulnerabilities
Vulnerable Software
Apple:  >> Mac Os X  >> 10.0.0  Security Vulnerabilities
libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by repeatedly connecting to the SSH port, a different vulnerability than CVE-2015-7761.
CVSS Score
5.0
EPSS Score
0.007
Published
2015-10-09
Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors.
CVSS Score
10.0
EPSS Score
0.02
Published
2015-10-09
Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified impact and attack vectors.
CVSS Score
5.0
EPSS Score
0.003
Published
2015-10-09
The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI update process by inserting an Apple Ethernet Thunderbolt adapter with crafted code in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists because of an incomplete fix for CVE-2014-4498.
CVSS Score
4.7
EPSS Score
0.001
Published
2015-10-09
Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request.
CVSS Score
6.8
EPSS Score
0.004
Published
2015-10-09
The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.
CVSS Score
4.9
EPSS Score
0.0
Published
2015-10-09
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.
CVSS Score
2.1
EPSS Score
0.001
Published
2015-10-09
The Address Book framework in Apple OS X before 10.11 allows local users to gain privileges by using an environment variable to inject code into processes that rely on this framework.
CVSS Score
4.6
EPSS Score
0.002
Published
2015-10-09
The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attackers to cause a denial of service (boot failure) via a crafted app that writes to an unintended address.
CVSS Score
7.1
EPSS Score
0.005
Published
2015-10-09
The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.
CVSS Score
4.3
EPSS Score
0.002
Published
2015-10-09


Contact Us

Shodan ® - All rights reserved