CVE-2015-7032
published 2015-10-18CVE-2015-7032: The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.04%
78.9th percentile
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iwork | <= 2.5.4 | — |
| apple | keynote | <= 6.5 | — |
| apple | keynote_6.6_pages_5.6_numbers_3.6_and_iwork_for_ios | — | — |
| apple | numbers | <= 3.5 | — |
| apple | pages | <= 5.5.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-7032: Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS 2.6
vendor_apple·CVSS 4.3
CVE-2015-7032 [MEDIUM] CVE-2015-7032: Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS 2.6
Apple Security Update: About the security content of Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS 2.6
Product: Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS
Version: 2.6
CVE: CVE-2015-7032
Component: CVE-ID
Impact: Opening a maliciously crafted document may lead to unexpected application termination or arbitrary code execution
Description: A memory corruption issue existed in parsing a maliciously crafted document. This issue was addressed through improved memory handling.
GHSA
GHSA-5wxw-67wh-rggh: The Apple iWork application before 2
ghsa_unreviewed·2022-05-17
CVE-2015-7032 [MEDIUM] CWE-200 GHSA-5wxw-67wh-rggh: The Apple iWork application before 2
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document.
No detection rules found.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.htmlhttp://www.securitytracker.com/id/1033823http://www.securitytracker.com/id/1033825http://www.securitytracker.com/id/1033826https://support.apple.com/HT205373http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.htmlhttp://www.securitytracker.com/id/1033823http://www.securitytracker.com/id/1033825http://www.securitytracker.com/id/1033826https://support.apple.com/HT205373
2015-10-18
Published