9.3

CVE-2024-44206

An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A user may be able to bypass some web content restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 17.6
Apple ≫ iPadOS Version < 17.6
Apple ≫ iPhone OS Version < 17.6
Apple ≫ macOS Version < 14.6
Apple ≫ tvOS Version < 17.6
Apple ≫ visionOS Version < 1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.375
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CISA-ADP 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://support.apple.com/en-us/120915
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120911
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120909
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120913
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120914
Vendor Advisory
Release Notes
https://support.apple.com/en-us/120916
Vendor Advisory
Release Notes
http://seclists.org/fulldisclosure/2024/Nov/6