TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2024-44144

MEDIUM
5.5

Beschreibung

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination.

CVE Details

CVSS v3.1 Bewertung5.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht10/28/2024
Zuletzt geandert4/2/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

apple:ipadosapple:iphone_osapple:macosapple:tvosapple:watchos

Schwachen (CWE)

CWE-120CWE-120

Referenzen

https://support.apple.com/en-us/121238(product-security@apple.com)
https://support.apple.com/en-us/121240(product-security@apple.com)
https://support.apple.com/en-us/121248(product-security@apple.com)
https://support.apple.com/en-us/121249(product-security@apple.com)
https://support.apple.com/en-us/121250(product-security@apple.com)
https://support.apple.com/en-us/121567(product-security@apple.com)
https://support.apple.com/en-us/121570(product-security@apple.com)
http://seclists.org/fulldisclosure/2024/Oct/10(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Oct/12(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.