CVE-2015-7033
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: product-security@apple.com — https://support.apple.com/HT205373
Vendor advisory: product-security@apple.com — http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.html
References
- http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.html
- http://www.securitytracker.com/id/1033823
- http://www.securitytracker.com/id/1033825
- http://www.securitytracker.com/id/1033826
- https://support.apple.com/HT205373
- http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.html
- http://www.securitytracker.com/id/1033823
- http://www.securitytracker.com/id/1033825
- http://www.securitytracker.com/id/1033826
- https://support.apple.com/HT205373
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.