5

CVE-2012-3698

Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonstrated by the keychain entries of a (1) helper tool or (2) command-line tool.

Data is provided by the National Vulnerability Database (NVD)
AppleXCode Version <= 4.3.3
AppleXCode Version1.5.0
AppleXCode Version2.0.0
AppleXCode Version2.1.0
AppleXCode Version2.2.0
AppleXCode Version2.3.0
AppleXCode Version2.4.0
AppleXCode Version2.4.1
AppleXCode Version3.1
AppleXCode Version3.1.1
AppleXCode Version3.1.2
AppleXCode Version3.1.3
AppleXCode Version3.1.4
AppleXCode Version3.2.1
AppleXCode Version3.2.2
AppleXCode Version3.2.3
AppleXCode Version3.2.4
AppleXCode Version3.2.5
AppleXCode Version4.0
AppleXCode Version4.0.1
AppleXCode Version4.0.2
AppleXCode Version4.1.1
AppleXCode Version4.2
AppleXCode Version4.2.1
AppleXCode Version4.3
AppleXCode Version4.3.1
AppleXCode Version4.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.455
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N