7.8

CVE-2015-1157

Exploit

CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleiPhone OS Version8.0
AppleiPhone OS Version8.0.1
AppleiPhone OS Version8.0.2
AppleiPhone OS Version8.1
AppleiPhone OS Version8.1.2
AppleiPhone OS Version8.1.3
AppleiPhone OS Version8.2
AppleiPhone OS Version8.3
ApplemacOS X Version <= 10.0.3
AppleiTunes Version <= 12.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.1% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C