CVE-2015-1154Out-of-bounds Write in Apple Iphone OS

11 documents4 sources
Severity
6.8MEDIUMNVD
EPSS
1.2%
top 21.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateMay 17

Description

WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1152 and CVE-2015-1153.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages6 packages

NVDapple/safari6.2.5+19
Ubuntuwebkitgtk/webkitgtk< 2.4.10-0ubuntu0.14.04.1+1
NVDapple/itunes12.2+1

🔴Vulnerability Details

6
GHSA
GHSA-xr42-288c-hwmj: WebKit, as used in Apple Safari before 62022-05-17
GHSA
GHSA-cj7g-46rv-89r4: WebKit, as used in Apple Safari before 62022-05-17
GHSA
GHSA-vpw8-6fwj-h438: WebKit, as used in Apple Safari before 62022-05-17
OSV
CVE-2015-1152: WebKit, as used in Apple Safari before 62015-05-08
OSV
CVE-2015-1154: WebKit, as used in Apple Safari before 62015-05-08

📋Vendor Advisories

2
Apple
CVE-2015-1154: iTunes 12.2
Apple
CVE-2015-1154: Safari 8.0.6, Safari 7.1.6, and Safari 6.2.6
CVE-2015-1154 — Out-of-bounds Write in Apple Iphone OS | cvebase