7.5
CVSSv2

CVE-2015-1103

Published: 10/04/2015 Updated: 08/03/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The kernel in Apple iOS prior to 8.3, Apple OS X prior to 10.10.3, and Apple TV prior to 7.2 makes routing changes in response to ICMP_REDIRECT messages, which allows remote malicious users to cause a denial of service (network outage) or obtain sensitive packet-content information via a crafted ICMP packet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple tvos

apple mac os x

Recent Articles

Apple patches FREAK-ed out Watch
The Register • Darren Pauli • 20 May 2015

Cupertino slings patches to kill twin data execution bugs

Apple has patched a dozen security flaws in Watch, including FREAK and two allowing arbitrary code execution. The updates cover Oracle hacker Marc Schoenefeld's arbitrary code execution which triggers (CVE-2015-1093) when the Apple Watch processes a maliciously crafted font file. It also squashes hacker Loki@ART's bug that grants malicious apps the ability to execute arbitrary code with system privileges via a kernel memory corruption issue (CVE-2015-1101). Apple closes the twin memory corruptio...