8.8

CVE-2022-42823

A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 16.1
Apple ≫ iPadOS Version < 16.0
Apple ≫ iPhone OS Version < 16.1
Apple ≫ macOS Version < 13.0
Apple ≫ tvOS Version < 16.1
Apple ≫ watchOS Version < 9.1
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Fedoraproject ≫ Fedora Version 37
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.47% 0.714
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://security.gentoo.org/glsa/202305-32
https://support.apple.com/en-us/HT213488
Vendor Advisory
http://www.openwall.com/lists/oss-security/2022/11/04/4
Third Party Advisory
Mailing List
https://support.apple.com/en-us/HT213489
Vendor Advisory
https://support.apple.com/en-us/HT213495
Vendor Advisory
https://support.apple.com/en-us/HT213491
Vendor Advisory
https://support.apple.com/en-us/HT213492
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2022/11/msg00010.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQKLEGJK3LHAKUQOLBHNR2DI3IUGLLTY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JOFKX6BUEJFECSVFV6P5INQCOYQBB4NZ/
https://www.debian.org/security/2022/dsa-5273
Third Party Advisory
https://www.debian.org/security/2022/dsa-5274
Third Party Advisory