CVE-2015-7000
published 2015-10-23CVE-2015-7000: Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
29.9th percentile
Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon after a setting was disabled.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.0.2 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FirePOWER 7000 and Cisco FirePOWER 8000 Series Inspection Engine Stall Vulnerability
vendor_cisco·2015-09-25·CVSS 6.1
CVE-2015-6307 [MEDIUM] CWE-399 Cisco FirePOWER 7000 and Cisco FirePOWER 8000 Series Inspection Engine Stall Vulnerability
Cisco FirePOWER 7000 and Cisco FirePOWER 8000 Series Inspection Engine Stall Vulnerability
A vulnerability in FireSIGHT System Software for Cisco FirePOWER 7000 Series and Cisco FirePOWER 8000 Series devices could allow an unauthenticated, adjacent attacker to cause the inspection engine to stop processing packets. Depending on the affected system configuration, this may cause traffic not to be inspected or to be dropped.
The vulnerability is due to improper parsing of crafted packets. An attacker could exploit this vulnerability by sending crafted packets to the affected system.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must have access to the same broadcast or collision domain as the targeted device. This access r
Cisco
Cisco Nexus 7000 Devices Virtual Device Context Privilege Escalation Vulnerability
vendor_cisco·2015-06-30·CVSS 3.6
CVE-2015-4231 [LOW] CWE-264 Cisco Nexus 7000 Devices Virtual Device Context Privilege Escalation Vulnerability
Cisco Nexus 7000 Devices Virtual Device Context Privilege Escalation Vulnerability
A privilege escalation vulnerability in the Python scripting subsystem of Cisco Nexus 7000 devices that have been configured with multiple virtual device contexts (VDCs) could allow an authenticated, local attacker to delete files owned by a different VDC on the device.
The vulnerability exists due to incomplete privilege separation of the Python scripting engine across multiple VDCs. An attacker with administrative privileges in a specific VDC could exploit this vulnerability to remove files owned by a separate VDC. This could result in a denial of service (DoS) condition on the affected device.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerab
Apple
CVE-2015-7000: iOS 9.1
vendor_apple·CVSS 2.1
CVE-2015-7000 [LOW] CVE-2015-7000: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7000
Component: CVE-ID
GHSA
GHSA-gm89-5jj3-5f7f: Notification Center in Apple iOS before 9
ghsa_unreviewed·2022-05-17
CVE-2015-7000 [LOW] CWE-200 GHSA-gm89-5jj3-5f7f: Notification Center in Apple iOS before 9
Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon after a setting was disabled.
No detection rules found.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.htmlhttp://www.securityfocus.com/bid/77268http://www.securitytracker.com/id/1033929https://support.apple.com/HT205370http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.htmlhttp://www.securityfocus.com/bid/77268http://www.securitytracker.com/id/1033929https://support.apple.com/HT205370
2015-10-23
Published