CVE-2009-2795
published 2009-09-10CVE-2009-2795: Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.37%
29.7th percentile
Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to "command parsing."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 3.1 | 3.1 |
| apple | iphone_os | < 3.1.1 | 3.1.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.htmlhttp://secunia.com/advisories/36677http://support.apple.com/kb/HT3860http://www.securityfocus.com/bid/36341https://exchange.xforce.ibmcloud.com/vulnerabilities/53183http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.htmlhttp://secunia.com/advisories/36677http://support.apple.com/kb/HT3860http://www.securityfocus.com/bid/36341https://exchange.xforce.ibmcloud.com/vulnerabilities/53183
2009-09-10
Published