7.8
CVSSv2

CVE-2015-1063

Published: 12/03/2015 Updated: 11/09/2015
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

CoreTelephony in Apple iOS prior to 8.2 allows remote malicious users to cause a denial of service (NULL pointer dereference and device restart) via a Class 0 SMS message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

Recent Articles

Apple slips out security patches while world goes gaga over watches
The Register • Shaun Nichols in San Francisco • 10 Mar 2015

Remote-code exec in iOS, OS X iCloud, plus FREAK fix

While everyone was losing their mind over expensive watches, Apple sneaked out security fixes for iOS phones and tablets, and OS X computers. Both the OS X Security Update 2015-002 and iOS 8.2 address critical flaws. Leading the charge is a patch to squish the FREAK bug in the two operating systems' SSL/TLS code. Disclosed last week by researchers, the flaw allows an eavesdropper to intercept connections to HTTPS websites and downgrade the strength of the encryption, allowing miscreants to crack...