9.8
CVSSv3

CVE-2017-2520

Published: 22/05/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in certain Apple products. iOS prior to 10.3.2 is affected. macOS prior to 10.12.5 is affected. tvOS prior to 10.2.1 is affected. watchOS prior to 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote malicious users to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted SQL statement.

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple tvos

apple mac os x

apple watchos

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in SQLite ...

Recent Articles

It's 2017 – and your Mac, iPad, iPhone can all be pwned by an e-book
The Register • Shaun Nichols in San Francisco • 16 May 2017

Seven Apple updates, because it's not like you had anything else to patch today

Apple has released security updates for both of its main operating systems, along with iTunes, Apple Watch, and Apple TV. All should be installed as soon as possible before they are exploited by miscreants. The updates, numbering seven in total, include fixes for security vulnerabilities in the Safari browser and WebKit engine. For iPhone and iPad, Apple has kicked out iOS 10.3.2. The update addresses a total of 41 CVE-listed vulnerabilities in the mobile OS, with 23 of those being flaws in WebK...