CVE-2015-1132
published 2015-04-10CVE-2015-1132: fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than…
PriorityP341critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.51%
88.0th percentile
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apple | mac_os_x | < 10.10.3 | 10.10.3 |
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_apache5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8chp-c6p4-xcv5: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1133 [HIGH] CWE-20 GHSA-8chp-c6p4-xcv5: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1134, and CVE-2015-1135.
GHSA
GHSA-vgj7-5chx-3pc8: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1132 [HIGH] CWE-20 GHSA-vgj7-5chx-3pc8: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
GHSA
GHSA-qrcw-fxf5-mcw6: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1135 [HIGH] CWE-20 GHSA-qrcw-fxf5-mcw6: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1134.
GHSA
GHSA-ghcq-pgwv-hvxp: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1134 [HIGH] CWE-20 GHSA-ghcq-pgwv-hvxp: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1135.
GHSA
GHSA-6x5j-jg26-j3c8: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-1131 [CRITICAL] CWE-20 GHSA-6x5j-jg26-j3c8: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1132, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
Apple
CVE-2015-1132: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 10.0
CVE-2015-1132 [CRITICAL] CVE-2015-1132: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2015-1132
Component: CVE-ID
Apache
Apache tika: CVE-2015-3271
vendor_apache·CVSS 5.3
CVE-2015-3271 [MEDIUM] Apache tika: CVE-2015-3271
Apache tika: CVE-2015-3271
Remote Access to host files via tika-server Tim Allison 1.9?-1.10 PDFBOX-2811 Apache PDFBox - Infinite Loop Andreas Lehmkühler ?-1.10 PDFBOX-2200 Apache PDFBox - Slowly building memory leak because of static caching of fonts Matthew Buckett ?-1.6 TIKA-1471 Apache PDFBox - OOM with corrupt PDF Alan Burlison ?-1.6 TIKA-788 Infinite Loop in DWG Stas Shaposhnikov ?-1.4? TIKA-1132 Apache POI - Nearly Infinite Loop in XLS Ryan Krueger ?-1.4 TIKA-1179 Infinite Loop in corrupt MP3 Marius Dumitru Florea ?-1.4 TIKA-866 OOM reading Tika config file Stephan Mühlstrasser ?-1.1 Third party vulnerabilities that may or may not be triggerable via regular use of Apache Tika. CVE or Vulnerability Description Reporter Affected Versions
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://www.securityfocus.com/bid/73982http://www.securitytracker.com/id/1032048https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://www.securityfocus.com/bid/73982http://www.securitytracker.com/id/1032048https://support.apple.com/HT204659
2015-04-10
Published