5.5

CVE-2023-42888

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version > 16.0 < 16.7.5
Apple ≫ iPadOS Version > 17.0 < 17.2
Apple ≫ iPhone OS Version > 16.0 < 16.7.5
Apple ≫ iPhone OS Version > 17.0 < 17.2
Apple ≫ macOS Version >= 12.0 < 12.7.3
Apple ≫ macOS Version >= 13.0 < 13.6.4
Apple ≫ macOS Version >= 14.0 < 14.2
Apple ≫ watchOS Version < 10.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.372
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.apple.com/kb/HT214036
Vendor Advisory
Release Notes
http://seclists.org/fulldisclosure/2024/Jan/34
Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jan/37
Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jan/38
Third Party Advisory
https://support.apple.com/kb/HT214058
https://support.apple.com/kb/HT214063
https://support.apple.com/kb/HT214035
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214036
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214035
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214041
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214058
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214057
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214063
Vendor Advisory
Release Notes
https://support.apple.com/kb/HT214041
Vendor Advisory
Release Notes