CVE-2015-1078: Medium severity itunes vulnerability
WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1078?
CVE-2015-1078 has a high severity due to its potential to allow remote code execution and cause application crashes.
How do I fix CVE-2015-1078?
To fix CVE-2015-1078, users should update their Apple Safari, iTunes, or tvOS to the latest versions that address this vulnerability.
Which software is affected by CVE-2015-1078?
CVE-2015-1078 affects several versions of Apple Safari, iTunes, and tvOS prior to their respective security updates.
Can CVE-2015-1078 be exploited by attackers?
Yes, CVE-2015-1078 can be exploited by attackers through crafted web pages to execute arbitrary code or cause denial of service.
Is there a workaround for CVE-2015-1078?
No specific workaround is recommended for CVE-2015-1078; updating to the patched versions is the most effective measure.