5.5

CVE-2024-23264

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, iOS 16.7.6 and iPadOS 16.7.6, tvOS 17.4. An application may be able to read restricted memory.

Data is provided by the National Vulnerability Database (NVD)
AppleiPadOS Version < 16.7.6
AppleiPadOS Version >= 17.0 < 17.4
AppleiPhone OS Version < 16.7.6
AppleiPhone OS Version >= 17.0 < 17.4
ApplemacOS Version >= 12.0 < 12.7.4
ApplemacOS Version >= 13.0 < 13.6.5
ApplemacOS Version >= 14.0 < 14.4
AppletvOS Version < 17.4
ApplevisionOS Version < 1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.265
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.