4.3

CVE-2018-4440

A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 12.0.2
Apple ≫ iPhone OS Version < 12.1.1
Apple ≫ iCloud Version < 7.9
   Microsoft ≫ Windows Version -
Apple ≫ iTunes Version < 12.9.2
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.62% 0.73
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://support.apple.com/kb/HT209340
Vendor Advisory
https://support.apple.com/kb/HT209344
Vendor Advisory
https://support.apple.com/kb/HT209345
Vendor Advisory
https://support.apple.com/kb/HT209346
Vendor Advisory