← Voltar para CVEs
CVE-2024-44144
MEDIUM5.5
Descricao
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination.
Detalhes CVE
Pontuacao CVSS v3.15.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Vetor de ataqueLOCAL
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado10/28/2024
Ultima modificacao4/2/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
apple:ipadosapple:iphone_osapple:macosapple:tvosapple:watchos
Fraquezas (CWE)
CWE-120CWE-120
Referencias
https://support.apple.com/en-us/121238(product-security@apple.com)
https://support.apple.com/en-us/121240(product-security@apple.com)
https://support.apple.com/en-us/121248(product-security@apple.com)
https://support.apple.com/en-us/121249(product-security@apple.com)
https://support.apple.com/en-us/121250(product-security@apple.com)
https://support.apple.com/en-us/121567(product-security@apple.com)
https://support.apple.com/en-us/121570(product-security@apple.com)
http://seclists.org/fulldisclosure/2024/Oct/10(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Oct/12(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.