The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted pointer value in the second argument.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Dec 2, 2015 | Nov 21, 2015 |
| Apple Osx Sqlite | — | Upgrade macOS to the latest version | Mar 29, 2016 | Nov 21, 2015 |
| Gentoo Linux | — | Upgrade dev-db/sqlite. | Oct 30, 2017 | Nov 21, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 23, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub