Severity
6.8MEDIUMNVD
EPSS
3.9%
top 11.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 15
Latest updateMay 1

Description

CoreText in Apple Mac OS X 10.4 through 10.4.10 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted text content that triggers an access of an uninitialized object pointer.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDapple/mac_os_x10.410.4.10

Patches

🔴Vulnerability Details

1
GHSA
GHSA-78x2-ww3j-6h5x: CoreText in Apple Mac OS X 102022-05-01

📐Framework References

2
CWE
Access of Uninitialized Pointer
CWE
Use of Uninitialized Variable