5.1

CVE-2012-3748

Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.

Data is provided by the National Vulnerability Database (NVD)
AppleSafari Version <= 6.0.1
AppleSafari Version1.0 Updatebeta
AppleSafari Version1.0 Updatebeta2
AppleSafari Version1.0.0
AppleSafari Version1.0.0b1
AppleSafari Version1.0.0b2
AppleSafari Version1.0.1
AppleSafari Version1.0.2
AppleSafari Version1.0.3
AppleSafari Version1.1.0
AppleSafari Version1.1.1
AppleSafari Version1.2.0
AppleSafari Version1.2.1
AppleSafari Version1.2.2
AppleSafari Version1.2.3
AppleSafari Version1.2.4
AppleSafari Version1.2.5
AppleSafari Version1.3
AppleSafari Version1.3.0
AppleSafari Version1.3.1
AppleSafari Version1.3.2
AppleSafari Version2.0.0
AppleSafari Version2.0.1
AppleSafari Version2.0.2
AppleSafari Version2.0.3
AppleSafari Version2.0.4
AppleSafari Version3.0.0
AppleSafari Version3.0.0b
AppleSafari Version3.0.1
AppleSafari Version3.0.1 Updatebeta
AppleSafari Version3.0.1b
AppleSafari Version3.0.2
AppleSafari Version3.0.2b
AppleSafari Version3.0.3
AppleSafari Version3.0.3b
AppleSafari Version3.0.4
AppleSafari Version3.0.4b
AppleSafari Version3.1.0
AppleSafari Version3.1.0b
AppleSafari Version3.1.1
AppleSafari Version3.1.2
AppleSafari Version3.2.0
AppleSafari Version3.2.1
AppleSafari Version3.2.2
AppleSafari Version4.0
AppleSafari Version4.0 Updatebeta
AppleSafari Version4.0.0b
AppleSafari Version4.0.1
AppleSafari Version4.0.2
AppleSafari Version4.0.3
AppleSafari Version4.0.4
AppleSafari Version4.0.5
AppleSafari Version4.1
AppleSafari Version4.1.1
AppleSafari Version4.1.2
AppleSafari Version5.0
AppleSafari Version5.0.1
AppleSafari Version5.0.2
AppleSafari Version5.0.4
AppleSafari Version5.0.5
AppleSafari Version5.0.6
AppleSafari Version5.1
AppleSafari Version5.1.1
AppleSafari Version5.1.2
AppleSafari Version5.1.3
AppleSafari Version5.1.4
AppleSafari Version5.1.5
AppleSafari Version5.1.6
AppleSafari Version5.1.7
AppleSafari Version6.0
AppleiPhone OS Version <= 6.0
AppleiPhone OS Version1.0.0
AppleiPhone OS Version1.0.1
AppleiPhone OS Version1.0.2
AppleiPhone OS Version1.1.0
AppleiPhone OS Version1.1.1
AppleiPhone OS Version1.1.2
AppleiPhone OS Version1.1.3
AppleiPhone OS Version1.1.4
AppleiPhone OS Version1.1.5
AppleiPhone OS Version2.0
AppleiPhone OS Version2.0.0
AppleiPhone OS Version2.0.1
AppleiPhone OS Version2.0.2
AppleiPhone OS Version2.1
AppleiPhone OS Version2.1.1
AppleiPhone OS Version2.2
AppleiPhone OS Version2.2.1
AppleiPhone OS Version3.0
AppleiPhone OS Version3.0.1
AppleiPhone OS Version3.1
AppleiPhone OS Version3.1.2
AppleiPhone OS Version3.1.3
AppleiPhone OS Version3.2
AppleiPhone OS Version3.2.1
AppleiPhone OS Version3.2.2
AppleiPhone OS Version4.0
AppleiPhone OS Version4.0.1
AppleiPhone OS Version4.0.2
AppleiPhone OS Version4.1
AppleiPhone OS Version4.2.1
AppleiPhone OS Version4.2.5
AppleiPhone OS Version4.2.8
AppleiPhone OS Version4.3.0
AppleiPhone OS Version4.3.1
AppleiPhone OS Version4.3.2
AppleiPhone OS Version4.3.3
AppleiPhone OS Version4.3.5
AppleiPhone OS Version5.0
AppleiPhone OS Version5.0.1
AppleiPhone OS Version5.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 30.42% 0.965
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.