8.1

CVE-2024-23263

A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

Data is provided by the National Vulnerability Database (NVD)
AppleSafari Version < 17.4
AppleiPadOS Version < 16.7.6
AppleiPadOS Version >= 17.0 < 17.4
AppleiPhone OS Version < 16.7.6
AppleiPhone OS Version >= 17.0 < 17.4
ApplemacOS Version >= 14.0 < 14.4
AppletvOS Version < 17.4
ApplevisionOS Version < 1.1
ApplewatchOS Version < 10.4
WebkitgtkWebkitgtk Version < 2.44.0
WpewebkitWpe Webkit Version < 2.44.0
FedoraprojectFedora Version38
FedoraprojectFedora Version39
FedoraprojectFedora Version40
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.4% 0.596
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.