7.3

CVE-2023-42875

Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 17.0
Apple ≫ iPadOS Version < 17.0
Apple ≫ iPhone OS Version < 17.0
Apple ≫ macOS Version < 14.0
Apple ≫ tvOS Version < 17.0
Apple ≫ watchOS Version < 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.3 2.1 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://support.apple.com/en-us/120950
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120949
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120330
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120947
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120948
Vendor Advisory
Release Notes