7.8

CVE-2022-22612

A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iTunes SwPlatform windows Version < 12.12.3
Apple ≫ iPadOS Version < 15.4
Apple ≫ iPhone OS Version < 15.4
Apple ≫ macOS Version >= 12.0 < 12.3
Apple ≫ tvOS Version < 15.4
Apple ≫ watchOS Version < 8.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.532
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/en-us/HT213182
Vendor Advisory
https://support.apple.com/en-us/HT213193
Vendor Advisory
https://support.apple.com/en-us/HT213183
Vendor Advisory
https://support.apple.com/en-us/HT213186
Vendor Advisory
https://support.apple.com/en-us/HT213188
Vendor Advisory