Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code via a crafted Collada file.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
http://www.securityfocus.com/bid/76340