CVE-2015-7036
The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 39.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted pointer value in the second argument.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 39.29% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/mac os x · apple/iphone os
- Source
- product-security@apple.com
References
- http://support.apple.com/kb/HT204941Vendor Advisory
- http://support.apple.com/kb/HT204942Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-15-570/
- https://security.gentoo.org/glsa/201612-21
- http://support.apple.com/kb/HT204941Vendor Advisory
- http://support.apple.com/kb/HT204942Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-15-570/
- https://security.gentoo.org/glsa/201612-21
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.