Apple watchOS vulnerabilities
1,895 known vulnerabilities affecting apple/watchos.
Total CVEs
1,895
CISA KEV
51
actively exploited
Public exploits
123
Exploited in wild
40
Severity breakdown
CRITICAL140HIGH970MEDIUM715LOW68UNKNOWN2
Vulnerabilities
Page 94 of 95
CVE-2015-5896HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5896 [HIGH] CVE-2015-5896: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.
nvd
CVE-2015-5843HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5843 [HIGH] CWE-119 CVE-2015-5843: IOMobileFrameBuffer in Apple iOS before 9 allows local users to gain privileges or cause a denial of
IOMobileFrameBuffer in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-5848HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5848 [HIGH] CWE-119 CVE-2015-5848: IOAcceleratorFamily in Apple iOS before 9 allows local users to gain privileges or cause a denial of
IOAcceleratorFamily in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-5874HIGHCVSS 7.5v1.02015-09-18
CVE-2015-5874 [HIGH] CWE-119 CVE-2015-5874: CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary c
CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2015-5899HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5899 [HIGH] CWE-119 CVE-2015-5899: libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a deni
libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-5868HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5868 [HIGH] CWE-119 CVE-2015-5868: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.
nvd
CVE-2015-5847HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5847 [HIGH] CWE-119 CVE-2015-5847: The Disk Images component in Apple iOS before 9 allows local users to gain privileges or cause a den
The Disk Images component in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-5916MEDIUMCVSS 4.3≤ 2.0.02015-09-18
CVE-2015-5916 [MEDIUM] CWE-200 CVE-2015-5916: The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-tra
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.
nvdapple
CVE-2015-5839MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5839 [MEDIUM] CWE-254 CVE-2015-5839: dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app
dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app that places a crafted signature in an executable file.
nvd
CVE-2015-5829MEDIUMCVSS 6.8v1.02015-09-18
CVE-2015-5829 [MEDIUM] CWE-119 CVE-2015-5829: Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cau
Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file.
nvd
CVE-2015-5855MEDIUMCVSS 4.3v1.02015-09-18
CVE-2015-5855 [MEDIUM] CWE-200 CVE-2015-5855: Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Ce
Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Center app.
nvd
CVE-2015-5860MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5860 [MEDIUM] CWE-200 CVE-2015-5860: The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remot
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.
nvd
CVE-2015-5837MEDIUMCVSS 4.3v1.02015-09-18
CVE-2015-5837 [MEDIUM] CWE-20 CVE-2015-5837: PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and ins
PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app.
nvd
CVE-2015-5840MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5840 [MEDIUM] CWE-119 CVE-2015-5840: The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial
The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial of service (overflow fault and app crash) via crafted data.
nvd
CVE-2015-5862MEDIUMCVSS 4.3v1.02015-09-18
CVE-2015-5862 [MEDIUM] CWE-119 CVE-2015-5862: The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memo
The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.
nvd
CVE-2015-5824MEDIUMCVSS 4.3v1.02015-09-18
CVE-2015-5824 [MEDIUM] CWE-310 CVE-2015-5824: The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly veri
The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2015-5885MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5885 [MEDIUM] CWE-200 CVE-2015-5885: The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vec
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
nvd
CVE-2015-5858MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5858 [MEDIUM] CWE-200 CVE-2015-5858: The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HST
The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.
nvd
CVE-2015-5834MEDIUMCVSS 4.3v1.02015-09-18
CVE-2015-5834 [MEDIUM] CWE-200 CVE-2015-5834: IOAcceleratorFamily in Apple iOS before 9 allows attackers to obtain sensitive kernel memory-layout
IOAcceleratorFamily in Apple iOS before 9 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
nvd
CVE-2015-5841MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5841 [MEDIUM] CWE-74 CVE-2015-5841: The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header w
The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
nvd