CVE-2015-1061
published 2015-03-12CVE-2015-1061: IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.21%
89.8th percentile
IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | about_security_update_2015-002 | — | — |
| apple | about_security_update_2015-003 | — | — |
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 8.1.3 | — |
| apple | mac_os_x | <= 10.10.2 | — |
| apple | tvos | <= 7.0.3 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-vm87-xq8q-f9xp: IOSurface in Apple iOS before 8
ghsa_unreviewed·2022-05-14
CVE-2015-1061 [HIGH] CWE-94 GHSA-vm87-xq8q-f9xp: IOSurface in Apple iOS before 8
IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.
Apple
CVE-2015-1061: About Security Update 2015-002
vendor_apple·CVSS 9.3
CVE-2015-1061 [CRITICAL] CVE-2015-1061: About Security Update 2015-002
Apple Security Update: About Security Update 2015-002
Product: About Security Update 2015-002
CVE: CVE-2015-1061
Component: CVE-ID
Apple
CVE-2015-1061: About Security Update 2015-003
vendor_apple·CVSS 9.3
CVE-2015-1061 [CRITICAL] CVE-2015-1061: About Security Update 2015-003
Apple Security Update: About Security Update 2015-003
Product: About Security Update 2015-003
CVE: CVE-2015-1061
Component: CVE-ID
Apple
CVE-2015-1061: iOS 8.2
vendor_apple·CVSS 9.3
CVE-2015-1061 [CRITICAL] CVE-2015-1061: iOS 8.2
Apple Security Update: About the security content of iOS 8.2
Product: iOS
Version: 8.2
CVE: CVE-2015-1061
Component: CVE-ID
Apple
CVE-2015-1061: Apple TV 7.1
vendor_apple·CVSS 9.3
CVE-2015-1061 [CRITICAL] CVE-2015-1061: Apple TV 7.1
Apple Security Update: About the security content of Apple TV 7.1
Product: Apple TV
Version: 7.1
CVE: CVE-2015-1061
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Mar/msg00002.htmlhttp://www.securityfocus.com/bid/73004http://www.securitytracker.com/id/1031864https://support.apple.com/HT204413https://support.apple.com/HT204423https://support.apple.com/HT204426https://support.apple.com/kb/HT204563http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Mar/msg00002.htmlhttp://www.securityfocus.com/bid/73004http://www.securitytracker.com/id/1031864https://support.apple.com/HT204413https://support.apple.com/HT204423https://support.apple.com/HT204426https://support.apple.com/kb/HT204563
2015-03-12
Published