Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2015-1100 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Iphone OS
Severity
5.4MEDIUMNVD
EPSS
0.8%
top 26.49%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 10
Latest updateMay 14
Description
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a crafted app.
CVSS vector
AV:L/AC:M/C:P/I:N/A:CExploitability: 3.4 | Impact: 7.8