CVE-2016-1757
high · 7Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a crafted app.
7
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2016-03-24
Published
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-362
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | iphone_os | <= 9.2.1 |
| apple | mac_os_x | <= 10.11.3 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
- http://www.securitytracker.com/id/1035353
- https://bugs.chromium.org/p/project-zero/issues/detail?id=676
- https://support.apple.com/HT206166
- https://support.apple.com/HT206167
- https://www.exploit-db.com/exploits/39595/
- https://www.exploit-db.com/exploits/39741/
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
- http://www.securitytracker.com/id/1035353
- https://bugs.chromium.org/p/project-zero/issues/detail?id=676
- https://support.apple.com/HT206166
- https://support.apple.com/HT206167
- https://www.exploit-db.com/exploits/39595/
- https://www.exploit-db.com/exploits/39741/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-1757