Vulnerabilities
Vulnerable Software
Apple:  >> Mac Os X  >> 10.7.3  Security Vulnerabilities
Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's URL.
CVSS Score
5.0
EPSS Score
0.005
Published
2015-01-30
The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the Gatekeeper protection mechanism by leveraging access to a revoked Developer ID certificate for signing a crafted app.
CVSS Score
4.3
EPSS Score
0.002
Published
2015-01-30
Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arbitrary code in a privileged context via a crafted app.
CVSS Score
9.3
EPSS Score
0.017
Published
2015-01-30
The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (arbitrary-size bzero of kernel memory) via a crafted app.
CVSS Score
10.0
EPSS Score
0.012
Published
2015-01-30
SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cache, which allows local users to read search results associated with other users' protected files via a Spotlight query.
CVSS Score
2.1
EPSS Score
0.001
Published
2015-01-30
The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, which allows local users to obtain sensitive information by reading from this drive.
CVSS Score
4.9
EPSS Score
0.001
Published
2015-01-30
security_taskgate in Apple OS X before 10.10.2 allows attackers to read group-ACL-restricted keychain items of arbitrary apps via a crafted app with a signature from a (1) self-signed certificate or (2) Developer ID certificate.
CVSS Score
5.0
EPSS Score
0.002
Published
2015-01-30
Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted accessor element in a Collada file.
CVSS Score
6.8
EPSS Score
0.036
Published
2015-01-30
SceneKit in Apple OS X before 10.10.2 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.
CVSS Score
7.5
EPSS Score
0.007
Published
2015-01-30
Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that includes a com.apple.sandbox segment in a path.
CVSS Score
7.5
EPSS Score
0.004
Published
2015-01-30


Contact Us

Shodan ® - All rights reserved