8.8

CVE-2021-30734

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 14.1.1
Apple ≫ iPadOS Version < 14.6
Apple ≫ iPhone OS Version < 14.6
Apple ≫ macOS Version >= 11.0.1 < 11.4
Apple ≫ tvOS Version < 14.6
Apple ≫ watchOS Version < 7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.01% 0.791
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/en-us/HT212528
Vendor Advisory
https://support.apple.com/en-us/HT212529
Vendor Advisory
https://support.apple.com/en-us/HT212532
Vendor Advisory
https://support.apple.com/en-us/HT212533
Vendor Advisory
https://support.apple.com/en-us/HT212534
Vendor Advisory