Unrated severityNVD Advisory· Published Sep 10, 2009· Updated Apr 23, 2026
CVE-2009-2795
CVE-2009-2795
Description
Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to "command parsing."
Affected products
2cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*range: <3.1
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:ipod_touch:*:*range: <3.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.apple.com/archives/security-announce/2009/Sep/msg00001.htmlnvdMailing ListPatchVendor Advisory
- support.apple.com/kb/HT3860nvdPatchVendor Advisory
- secunia.com/advisories/36677nvdVendor Advisory
- www.securityfocus.com/bid/36341nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/53183nvdVDB Entry
News mentions
0No linked articles in our index yet.