5
CVSSv2

CVE-2015-1105

Published: 10/04/2015 Updated: 08/03/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The TCP implementation in the kernel in Apple iOS prior to 8.3, Apple OS X prior to 10.10.3, and Apple TV prior to 7.2 does not properly implement the Urgent (aka out-of-band data) mechanism, which allows remote malicious users to cause a denial of service via crafted packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple iphone os

apple tvos

Recent Articles

Apple patches FREAK-ed out Watch
The Register • Darren Pauli • 20 May 2015

Cupertino slings patches to kill twin data execution bugs

Apple has patched a dozen security flaws in Watch, including FREAK and two allowing arbitrary code execution. The updates cover Oracle hacker Marc Schoenefeld's arbitrary code execution which triggers (CVE-2015-1093) when the Apple Watch processes a maliciously crafted font file. It also squashes hacker Loki@ART's bug that grants malicious apps the ability to execute arbitrary code with system privileges via a kernel memory corruption issue (CVE-2015-1101). Apple closes the twin memory corruptio...

iOS, OS X apps sent into infinite dizzy DoS by this one weird kernel bug
The Register • Darren Pauli • 09 Apr 2015

Apple patches OOB boob to stop API noobs being duped

Kenton Varda has found a 'weird' kernel bug used in Apple gear that could result in trivial denial of service by remote attackers. The hacker and LAN gamer bod says the Darwin kernel vulnerability (CVE-2015-1105) now patched by Cupertino for iOS and OS X is "no Shellshock" but could cause apps like Google Chrome to crash and Node.js to spin into infinite loops when OOB data is received. Varda (@kentonvarda) says he found the bug while probing operating systems event I/O interfaces. "Technically ...