Vulnerability Name: | CVE-2017-7005 (CCN-139704) | ||||||||||||
Assigned: | 2017-03-17 | ||||||||||||
Published: | 2018-02-27 | ||||||||||||
Updated: | 2019-03-08 | ||||||||||||
Summary: | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
8.6 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-7005 Source: CCN Type: Google Security Research Issue 1208 WebKit: JSC: JSGlobalObject::haveABadTime causes type confusions Source: XF Type: UNKNOWN sony-cve20177005-code-exec(139704) Source: MISC Type: Exploit, Third Party Advisory https://github.com/Quindecim/Orbis-Exploit-5.x Source: CCN Type: Packet Storm Security [02-27-2018] Sony Playstation 4 (PS4) 5.0x Code Execution Source: CCN Type: Packet Storm Security [03-13-2018] Sony Playstation 4 (PS4) WebKit Code Execution Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT207798 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT207801 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT207804 Source: EXPLOIT-DB Type: Exploit, Third Party Advisory, VDB Entry 42188 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [02-27-2018] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [03-10-2018] Source: CCN Type: Sony Web site PlayStation 4 | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |