CVE-2015-3774 - Theriomorphic Sash
Description
The Dictionary app in Apple OS X before 10.10.5 does not use HTTPS which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof word definitions by modifying the client-server data stream.
Reference
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html https://support.apple.com/kb/HT205031 http://www.securityfocus.com/bid/76340 http://www.securitytracker.com/id/1033276