cbcvebase.
CVE-2015-5844
published 2015-09-18

CVE-2015-5844: IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption)…

PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.70%
84.4th percentile
IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5845 and CVE-2015-5846.

Affected

6 ranges
VendorProductVersion rangeFixed in
appleios_9
appleiphone_os<= 8.4.1
applewatchos
applewatchos_2
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.33.1.2-7ubuntu2.3
libarchivelibarchive>= 0 < 3.1.2-11ubuntu0.16.04.23.1.2-11ubuntu0.16.04.2

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.