CVE-2015-7036
high · 7.5The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted pointer value in the second argument.
7.5
CVSS
39.3%
EPSS (exploit prob.)
99th
EPSS percentile
2015-11-22
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | mac_os_x | <= 10.10.3 |
| apple | iphone_os | <= 8.3 |
Check a specific version with /api/v1/cve/match.
References
- http://support.apple.com/kb/HT204941
- http://support.apple.com/kb/HT204942
- http://zerodayinitiative.com/advisories/ZDI-15-570/
- https://security.gentoo.org/glsa/201612-21
- http://support.apple.com/kb/HT204941
- http://support.apple.com/kb/HT204942
- http://zerodayinitiative.com/advisories/ZDI-15-570/
- https://security.gentoo.org/glsa/201612-21
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-7036