CVE-2015-3717: Apple iPhone OS

High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.

Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

Affected products

  • Apple iPhone OS: before 8.4 (fixed in 8.4)
  • Apple Mac OS X: before 10.10.4 (fixed in 10.10.4)
  • Sqlite Sqlite: before 3.8.9 (fixed in 3.8.9)

Published 2015-07-03. Last modified 2026-06-17.