7.1
CVSSv2

CVE-2015-1102

Published: 10/04/2015 Updated: 08/03/2019
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The kernel in Apple iOS prior to 8.3, Apple OS X prior to 10.10.3, and Apple TV prior to 7.2 does not properly handle TCP headers, which allows man-in-the-middle malicious users to cause a denial of service via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple iphone os

apple tvos

Recent Articles

Apple patches FREAK-ed out Watch
The Register • Darren Pauli • 20 May 2015

Cupertino slings patches to kill twin data execution bugs

Apple has patched a dozen security flaws in Watch, including FREAK and two allowing arbitrary code execution. The updates cover Oracle hacker Marc Schoenefeld's arbitrary code execution which triggers (CVE-2015-1093) when the Apple Watch processes a maliciously crafted font file. It also squashes hacker Loki@ART's bug that grants malicious apps the ability to execute arbitrary code with system privileges via a kernel memory corruption issue (CVE-2015-1101). Apple closes the twin memory corruptio...