Show filters
191 Total Results
Displaying 1-10 of 191
Sort by:
Attacker Value
Unknown
CVE-2021-23841
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1…
0
Attacker Value
Unknown
CVE-2015-5896
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.
0
Attacker Value
Unknown
CVE-2015-5876
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
dyld in Dev Tools in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
0
Attacker Value
Unknown
CVE-2015-5885
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
0
Attacker Value
Unknown
CVE-2015-5869
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
0
Attacker Value
Unknown
CVE-2015-5868
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.
0
Attacker Value
Unknown
CVE-2015-5874
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
0
Attacker Value
Unknown
CVE-2015-5882
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.
0
Attacker Value
Unknown
CVE-2015-5863
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
0
Attacker Value
Unknown
CVE-2015-5899
Disclosure Date: September 18, 2015 (last updated October 05, 2023)
libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
0