CVE-2015-1066
published 2015-03-12CVE-2015-1066: Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
PriorityP346critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.77%
84.8th percentile
Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | about_security_update_2015-002 | — | — |
| apple | mac_os_x | <= 10.10.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-1066: About Security Update 2015-002
vendor_apple·CVSS 10.0
CVE-2015-1066 [CRITICAL] CVE-2015-1066: About Security Update 2015-002
Apple Security Update: About Security Update 2015-002
Product: About Security Update 2015-002
CVE: CVE-2015-1066
Component: CVE-ID
GHSA
GHSA-h4vr-mppx-f2fr: Off-by-one error in IOAcceleratorFamily in Apple OS X through 10
ghsa_unreviewed·2022-05-17
CVE-2015-1066 [HIGH] GHSA-h4vr-mppx-f2fr: Off-by-one error in IOAcceleratorFamily in Apple OS X through 10
Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4603 php: exception::getTraceAsString type confusion issue after unserialize
bugzilla·2015-06-17·CVSS 9.8
CVE-2015-4603 [CRITICAL] CVE-2015-4603 php: exception::getTraceAsString type confusion issue after unserialize
CVE-2015-4603 php: exception::getTraceAsString type confusion issue after unserialize
A type confusion issue was found in exception::getTraceAsString(). If a specially crafted input is unserialized, it could lead to information leak and possibly code execution.
The issue was reported upstream in:
https://bugs.php.net/bug.php?id=69152#1425357025
and was corrected in:
http://git.php.net/?p=php-src.git;a=commitdiff;h=a894a8155fab068d68a04bf181dbaddfa01ccbb0
See also bug 1222538 comment 7.
Discussion:
This issue was already corrected in Red Hat Software Collections php54 collection in Red Hat Software Collections 2.0, when php54-php component was updated to the fixed upstream version 5.4.40:
https://rhn.redhat.com/errata/RHSA-2015-1066.html
---
This issue has been addressed in the f
Bugzilla
CVE-2015-4602 php: Incomplete Class unserialization type confusion
bugzilla·2015-06-17·CVSS 9.8
CVE-2015-4602 [CRITICAL] CVE-2015-4602 php: Incomplete Class unserialization type confusion
CVE-2015-4602 php: Incomplete Class unserialization type confusion
A type confusion issue was found in the way PHP performed unserialization of incomplete class. If a specially crafted input is unserialized, it could lead to information leak and possibly code execution.
The issue was reported upstream in:
https://bugs.php.net/bug.php?id=69152#1426863482
and was corrected in:
http://git.php.net/?p=php-src.git;a=commitdiff;h=fb83c76deec58f1fab17c350f04c9f042e5977d1
See also bug 1222538 comment 7.
Discussion:
This issue was already corrected in Red Hat Software Collections php54 collection in Red Hat Software Collections 2.0, when php54-php component was updated to the fixed upstream version 5.4.40:
https://rhn.redhat.com/errata/RHSA-2015-1066.html
---
This issue has been addressed
2015-03-12
Published