8.8

CVE-2016-4762

WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, iCloud before 6.0 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version <= 9.1.3
Apple ≫ iPhone OS Version <= 9.3.5
Apple ≫ iCloud Version 5.2.1
   Microsoft ≫ Windows
Apple ≫ iTunes Version 12.4.3
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.19% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html
Vendor Advisory
Mailing List
https://support.apple.com/HT207143
Vendor Advisory
http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html
Vendor Advisory
Mailing List
http://www.securitytracker.com/id/1036854
https://support.apple.com/HT207157
Vendor Advisory
http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html
Vendor Advisory
Mailing List
https://support.apple.com/HT207158
Vendor Advisory
http://www.securityfocus.com/bid/93066
http://lists.apple.com/archives/security-announce/2016/Sep/msg00013.html
Vendor Advisory
Mailing List
https://support.apple.com/HT207147
Vendor Advisory