tl;dr Apple Safari for OS X was prone to URI spoofing vulnerability (and more general a user interface spoofing).
Apple released security updates for Safari 9<https://support.apple.com/kb/HT205265> on OS X and assigned CVE-2015-5764.
Accidentally this vulnerability was also present in iOS.
Could you be a little more clear with the process for number 5, the account hijack and contact import? Isn’t
intercepting the 5-digit code sufficient to gain account takeover?
-J
This is a copied version of my blog post, original version http://justhaifei1.blogspot.com/2015/10/watch-your-downloads-risk-of-auto.html.Probably it’s commonly known that when
you try to download something on your modern browser e.g. Google Chrome or Microsoft Edge, the file will be downloaded
automatically to your local system with just a simple clicking – no need for additional confirmations. With default
settings, the file will be…
(Sorry for the “CVE-2015-ABCD” place-holders in the report, but
OpenSMTPD’s developers were ready with the patches before MITRE was
ready with the CVE-IDs.)
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says “It was determined that this is a longtime behavior of Python that cannot really be altered at this point.” (CVSS:7.2) (Last Update:2015-10-07)
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX001 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not have an off autocomplete attribute for the password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly encrypt passwords, which makes it easier for context-dependent attackers to determine cleartext passwords by leveraging access to a password file.