CVE-2015-1132Improper Input Validation in Apple MAC OS X

Severity
10.0CRITICALNVD
NVD7.2
EPSS
1.1%
top 21.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 14

Description

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

🔴Vulnerability Details

5
GHSA
GHSA-8chp-c6p4-xcv5: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-vgj7-5chx-3pc8: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-qrcw-fxf5-mcw6: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-ghcq-pgwv-hvxp: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-6x5j-jg26-j3c8: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14

📋Vendor Advisories

2
Apple
CVE-2015-1132: OS X Yosemite v10.10.3 and Security Update 2015-004
Apache
Apache tika: CVE-2015-3271

💬Community

1
Bugzilla
CVE-2015-4467 CVE-2015-4472 libmspack: denial of service while processing crafted CHM file (floating point exception)2015-01-08