Show filters
225 Total Results
Displaying 31-40 of 225
Sort by:
Attacker Value
Unknown

CVE-2015-5312

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
0
Attacker Value
Unknown

CVE-2015-8242

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
0
Attacker Value
Unknown

CVE-2014-4462

Disclosure Date: November 18, 2014 (last updated October 05, 2023)
WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4452.
0
Attacker Value
Unknown

CVE-2014-4461

Disclosure Date: November 18, 2014 (last updated October 05, 2023)
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
0
Attacker Value
Unknown

CVE-2014-4455

Disclosure Date: November 18, 2014 (last updated October 05, 2023)
dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.
0
Attacker Value
Unknown

CVE-2014-3192

Disclosure Date: October 08, 2014 (last updated October 05, 2023)
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-4419

Disclosure Date: September 18, 2014 (last updated October 05, 2023)
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4420, and CVE-2014-4421.
0
Attacker Value
Unknown

CVE-2014-4410

Disclosure Date: September 18, 2014 (last updated October 05, 2023)
WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.
0
Attacker Value
Unknown

CVE-2014-4418

Disclosure Date: September 18, 2014 (last updated November 25, 2024)
IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4388.
0
Attacker Value
Unknown

CVE-2014-4372

Disclosure Date: September 18, 2014 (last updated October 05, 2023)
syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.
0